logo

Tomcat in the Crosshairs: New Research Reveals Ongoing Attacks

ID: 7a1098b1-2f2c-55ac-8e44-d5eb308e9b1f

STIX ID: report--7a1098b1-2f2c-55ac-8e44-d5eb308e9b1f

Feed Name: Aqua Security Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-04-26

...
...

Aqua Nautilus researchers describe an active 2025 campaign targeting Apache Tomcat servers that uses brute-force/management-console abuse and a recently disclosed Tomcat vulnerability to upload JSP web shells that decode AES-encrypted payloads, establish persistence, and deliver packed ELF and Windows binaries which steal SSH keys, move laterally, and run cryptomining workloads; the report includes code excerpts, dynamic analysis of the packed ELF (anti-debugging, socket use, process masquerading), IOCs (IPs, domain dbliker.top, multiple MD5s), and recommended mitigations such as patching, disabling unused management interfaces, network segmentation, and runtime protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.