logo

New Linux malware Hadooken targets Oracle WebLogic servers

ID: 59237f96-0f10-5c70-8dd5-f0ce59234150

STIX ID: report--59237f96-0f10-5c70-8dd5-f0ce59234150

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-09-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Aqua Security observed a campaign abusing weak credentials on Oracle WebLogic servers to deploy a Linux malware family dubbed "Hadooken," which installs a cryptominer and the Tsunami DDoS bot, persists via randomized cron jobs and process renaming, searches for SSH keys to lateralize, and wipes logs; researchers also found links to ransomware (Mallox and references to RHOMBUS/NoEscape) on infrastructure used by the operator.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.