Threat Advisory

Hadooken Malware Exploiting Oracle WebLogic Servers for Cryptomining and DDoS Attacks

Threat: Malware
Targeted Region: Global
Threat Actor Region: Russia & Germany
Targeted Sector: Technology & IT, Finance & Banking, Retail & E-Commerce
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have identified a new Linux malware named Hadooken, specifically targeting Oracle WebLogic servers. The name appears to reference the “surge fist” attack from the Street Fighter series. This malware, upon execution, not only drops Tsunami malware but also deploys a cryptominer, posing significant risks to organizations that rely on WebLogic for their enterprise applications. Given the common vulnerabilities associated with WebLogic servers, such as deserialization flaws and improper access controls, the potential for exploitation remains high, especially if misconfigurations exist.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Researchers have identified a new Linux malware named Hadooken, specifically targeting Oracle WebLogic servers. The name appears to reference the “surge fist” attack from the Street Fighter series. This malware, upon execution, not only drops Tsunami malware but also deploys a cryptominer, posing significant risks to organizations that rely on WebLogic for their enterprise applications. Given the common vulnerabilities associated with WebLogic servers, such as deserialization flaws and improper access controls, the potential for exploitation remains high, especially if misconfigurations exist.[emaillocker id="1283"]

The attack begins with the exploitation of weak passwords on vulnerable WebLogic servers, allowing threat actors to gain remote code execution. Once inside, they execute a primary payload that downloads two scripts: a shell script (‘c’) and a Python script (‘y’). The shell script installs Hadooken directly into the '/tmp' directory, while the Python script attempts to download and run Hadooken in non-persistent temporary directories. Both scripts are designed to execute the malware and remove any traces of their presence. Upon execution, Hadooken drops two ELF files: a packed cryptominer and Tsunami malware, the latter being placed in a random temporary directory. The cryptominer is strategically located in multiple paths to ensure persistence through cron jobs, which are created with random names and executed periodically. Additionally, indicators suggest that the threat actor is attempting to leverage existing SSH data to move laterally within networks. Analysis of the malware also revealed potential links to known ransomware variants, hinting at the possibility of further malicious activities.

The emergence of Hadooken malware highlights the need for vigilant security practices, particularly for organizations utilizing WebLogic servers. Employing comprehensive security measures, such as Infrastructure as Code (IaC) scanning tools and Cloud Security Posture Management (CSPM) solutions, can help mitigate the risks associated with misconfigurations and vulnerabilities. Continuous monitoring and detection capabilities, as demonstrated by detection of suspicious activities during the attack, are crucial for identifying and responding to threats in real time. As attackers increasingly target enterprise environments, proactive security strategies are essential for protecting sensitive data and maintaining system integrity.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access  T1190 Exploit Public-Facing Application
Execution T1059 Command and Scripting Interpreter
Persistence T1543 Create or Modify System Process
Defense Evasion T1027 Obfuscated Files or Information
T1036 Masquerading
T1070 Indicator Removal
T1550 Use Alternate Authentication Material
 Credential Access T1110 Brute Force
Impact T1486 Data Encrypted for Impact
T1496 Resource Hijacking

 

REFERENCES:

The following reports contain further technical details:
https://www.darkreading.com/cyberattacks-data-breaches/hadooken-malware-targets-weblogic-servers

[/emaillocker]
crossmenu