Exposed JDWP Exploited in the Wild: What Happens When Debug Ports Are Left Open
ID: d25dc3d7-5b60-5d24-96ec-d7f8db6ea197
STIX ID: report--d25dc3d7-5b60-5d24-96ec-d7f8db6ea197
Feed Name: Wiz Blog
Threat Score
Researchers observed rapid exploitation of exposed JDWP on a TeamCity honeypot that allowed attackers to use JDWP protocol commands to invoke Runtime.exec and fetch a dropper (logservice.sh). The dropper installs a customized XMRig miner named 'logrotate', removes competing miners, and establishes persistence via shell startup files, systemd, rc.local, and multiple cron jobs; the report includes hashes, IPs, domains, and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
