FritzFrog Returns with Log4Shell and PwnKit, Spreading Malware Inside Your Network
ID: 47c7a8a0-8a16-56d3-9c90-ec53e07eac3e
STIX ID: report--47c7a8a0-8a16-56d3-9c90-ec53e07eac3e
Feed Name: The Hacker News
Akamai reports that the FritzFrog P2P botnet has reemerged with a variant dubbed Frog4Shell that exploits the Log4Shell vulnerability to propagate laterally inside already-compromised networks, while continuing SSH brute-force attacks against internet-facing servers; it also leverages PwnKit (CVE-2021-4034) for local privilege escalation and uses memory-resident execution (e.g., /dev/shm and memfd_create) to avoid disk-based detection, enabling deployment of cryptocurrency miners and DDoS-capable infections across sectors including healthcare, education, and government.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
