Lucifer DDoS botnet Malware is Targeting Apache Big-Data Stack
ID: 650e4638-9fca-5743-af74-f487b918e4a5
STIX ID: report--650e4638-9fca-5743-af74-f487b918e4a5
Feed Name: Aqua Security Blog
Threat Score
Aqua Nautilus describes an ongoing campaign (observed July 2023 through January 2024 and ongoing) in which operators exploit Apache Hadoop YARN misconfigurations and Apache Druid CVE‑2021‑25646 to install Lucifer DDoS/cryptomining malware; the attack chain uses staged droppers to deploy XMRig miners, employs persistence (cron), defense-evasion (binary deletion, packing, log truncation), and includes comprehensive IOCs (attacker/C2 IPs, domains, file hashes, and a wallet).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
