Hadooken Malware Targets Weblogic Applications
Essential information
- Published
- 13/09/2024 09:13
- Modified
- 13/09/2024 09:26
- Tags
- 2024-09-13 backdoor cryptocurrency hadooken lateral movement linux mallox tsunami weblogic
- Related entities
- 4 observables, 9 techniques (mitre), 3 malware
Description
Aqua Nautilus researchers identified a Linux malware, named Hadooken, targeting Oracle WebLogic servers. Upon gaining initial access through an exploited weak password, Hadooken deploys a cryptominer and the Tsunami malware. The report details the attack flow, techniques employed by the threat actors, including remote code execution, persistence mechanisms, and lateral movement. It also provides Indicators of Compromise (IOCs) and recommendations for detecting and mitigating such attacks.