New Linux malware Hadooken targets Oracle WebLogic servers
ID: 59237f96-0f10-5c70-8dd5-f0ce59234150
STIX ID: report--59237f96-0f10-5c70-8dd5-f0ce59234150
Feed Name: Bleeping Computer
Threat Score
Aqua Security observed a campaign abusing weak credentials on Oracle WebLogic servers to deploy a Linux malware family dubbed "Hadooken," which installs a cryptominer and the Tsunami DDoS bot, persists via randomized cron jobs and process renaming, searches for SSH keys to lateralize, and wipes logs; researchers also found links to ransomware (Mallox and references to RHOMBUS/NoEscape) on infrastructure used by the operator.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
