Tomcat Under Attack: Exploring Mirai Malware and Beyond
ID: b6953367-5e95-5818-8d9f-d6d7329b5b4e
STIX ID: report--b6953367-5e95-5818-8d9f-d6d7329b5b4e
Feed Name: Aqua Security Blog
This report analyzes more than 800 attacks observed against Apache Tomcat honeypots over two years and identifies a predominant Mirai-related campaign that brute‑forces Tomcat web manager credentials (including default credentials), uploads WAR files containing web shells (e.g., cmd.jsp), and executes a 'neww' shell script to fetch and run architecture-specific Mirai binaries (for DDoS and cryptomining). It documents the attack flow, defense-evasion techniques (history clearing), detection via CNDR/eBPF, provides attacker and malware IOCs (IP addresses, malware hosts, filenames and SHA256 hashes), and recommends securing configurations, rotating credentials, and deploying runtime detection and scanning tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
