logo

Tomcat Under Attack: Exploring Mirai Malware and Beyond

ID: b6953367-5e95-5818-8d9f-d6d7329b5b4e

STIX ID: report--b6953367-5e95-5818-8d9f-d6d7329b5b4e

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2023-07-26

Date Updated: 2026-04-26

...
...

This report analyzes more than 800 attacks observed against Apache Tomcat honeypots over two years and identifies a predominant Mirai-related campaign that brute‑forces Tomcat web manager credentials (including default credentials), uploads WAR files containing web shells (e.g., cmd.jsp), and executes a 'neww' shell script to fetch and run architecture-specific Mirai binaries (for DDoS and cryptomining). It documents the attack flow, defense-evasion techniques (history clearing), detection via CNDR/eBPF, provides attacker and malware IOCs (IP addresses, malware hosts, filenames and SHA256 hashes), and recommends securing configurations, rotating credentials, and deploying runtime detection and scanning tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.