Apache Applications Targeted by Stealthy Attacker
ID: 632d2d33-a52a-5e2d-97da-3fbdc815c724
STIX ID: report--632d2d33-a52a-5e2d-97da-3fbdc815c724
Feed Name: Aqua Security Blog
Threat Score
Aqua Nautilus researchers uncovered an active campaign exploiting unauthenticated RCE misconfigurations in Apache Hadoop YARN and Apache Flink to drop a packed ELF downloader ('dca') that installs two process-hiding rootkits and a Monero cryptominer, achieves persistence via cronjobs, and communicates with staging servers (several IPs and ns1.disponibletogether.com); the report provides IOCs, MITRE ATT&CK mappings, and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
