logo

Threat Alert: Tracking Real-World Apache Log4j Attacks

ID: 15a4296a-45f7-5c6a-8033-a82fb9bd4aae

STIX ID: report--15a4296a-45f7-5c6a-8033-a82fb9bd4aae

Feed Name: Aqua Security Blog

Threat Score
90/100

Date Published: 2021-12-17

Date Updated: 2026-04-26

...
...

This report documents real-world exploitation of the critical Log4j (CVE-2021-44228) vulnerability observed by Aqua Security via honeypots: multiple botnets and attackers exploited JNDI lookups to deliver malware (Muhstik, Mirai), open reverse shells, and execute payloads directly in memory to evade detection; the report includes IoCs (IPs, MD5 hashes, sample payloads) and recommends detection via a Java Trace-Agent hooking the JNDI lookup.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.