logo

'Lucifer' Botnet Turns Up the Heat on Apache Hadoop Servers

ID: 9e831e41-e64e-568b-beef-bc7a66c6e08f

STIX ID: report--9e831e41-e64e-568b-beef-bc7a66c6e08f

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-02-21

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Aqua Nautilus researchers have observed a multi-phase campaign using the Lucifer botnet to target misconfigured Apache big-data platforms (Hadoop, Druid, Flink). The attackers scanned for vulnerable or misconfigured instances, exploited Hadoop YARN misconfigurations and CVE-2021-25646 in Apache Druid to download and execute Lucifer, which provides cryptomining and DDoS capabilities; the campaign shows testing of evasion techniques and staged delivery to improve persistence and bypass detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.