logo

Lucifer DDoS botnet Malware is Targeting Apache Big-Data Stack

ID: 650e4638-9fca-5743-af74-f487b918e4a5

STIX ID: report--650e4638-9fca-5743-af74-f487b918e4a5

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2024-02-21

Date Updated: 2026-04-26

...
...

Aqua Nautilus describes an ongoing campaign (observed July 2023 through January 2024 and ongoing) in which operators exploit Apache Hadoop YARN misconfigurations and Apache Druid CVE‑2021‑25646 to install Lucifer DDoS/cryptomining malware; the attack chain uses staged droppers to deploy XMRig miners, employs persistence (cron), defense-evasion (binary deletion, packing, log truncation), and includes comprehensive IOCs (attacker/C2 IPs, domains, file hashes, and a wallet).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.