logo

Exposed JDWP Exploited in the Wild: What Happens When Debug Ports Are Left Open

ID: d25dc3d7-5b60-5d24-96ec-d7f8db6ea197

STIX ID: report--d25dc3d7-5b60-5d24-96ec-d7f8db6ea197

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2025-07-02

Date Updated: 2026-05-01

...
...

Researchers observed rapid exploitation of exposed JDWP on a TeamCity honeypot that allowed attackers to use JDWP protocol commands to invoke Runtime.exec and fetch a dropper (logservice.sh). The dropper installs a customized XMRig miner named 'logrotate', removes competing miners, and establishes persistence via shell startup files, systemd, rc.local, and multiple cron jobs; the report includes hashes, IPs, domains, and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.