logo

FritzFrog Returns with Log4Shell and PwnKit, Spreading Malware Inside Your Network

ID: 47c7a8a0-8a16-56d3-9c90-ec53e07eac3e

STIX ID: report--47c7a8a0-8a16-56d3-9c90-ec53e07eac3e

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Akamai reports that the FritzFrog P2P botnet has reemerged with a variant dubbed Frog4Shell that exploits the Log4Shell vulnerability to propagate laterally inside already-compromised networks, while continuing SSH brute-force attacks against internet-facing servers; it also leverages PwnKit (CVE-2021-4034) for local privilege escalation and uses memory-resident execution (e.g., /dev/shm and memfd_create) to avoid disk-based detection, enabling deployment of cryptocurrency miners and DDoS-capable infections across sectors including healthcare, education, and government.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.