logo

Hadooken Malware Targets Weblogic Applications

ID: 6552cd9f-81c4-553e-89d5-d8622f22ab8c

STIX ID: report--6552cd9f-81c4-553e-89d5-d8622f22ab8c

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2024-09-12

Date Updated: 2026-04-26

...
...

Aqua Nautilus discovered and analyzed Hadooken, a Linux malware campaign targeting exposed or misconfigured Oracle WebLogic servers: attackers gain access via weak credentials, deploy scripts that fetch and execute Hadooken, which drops a cryptominer and a Tsunami binary, establishes persistence via randomized cronjobs, attempts SSH credential harvesting for lateral movement, and includes IOCs (two attacker IPs and multiple MD5 hashes) and MITRE ATT&CK mappings alongside detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.