The gift that keeps on giving: A new opportunistic Log4j campaign
ID: 7f8800cd-7155-561d-b31e-f5d3a76f9678
STIX ID: report--7f8800cd-7155-561d-b31e-f5d3a76f9678
Feed Name: Datadog Security Labs
Threat Score
This report documents an opportunistic campaign exploiting Log4Shell (CVE-2021-44228) to deliver a malicious Java class that downloads and runs an obfuscated bash payload (lte), which installs an XMRig crypto-miner, sets persistence via systemd or cron, deploys multiple encrypted/backdoor shells, performs system reconnaissance and exfiltrates data; the write-up includes decompiled Java code, script behaviour, IPs/domains, file hashes, and Datadog detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
