Hackers used the Log4Shell vulnerability to install hidden miners
The experts have identified attacks aimed at devices running Linux

13.12.2021 - 12:20
357
1 min
0
.
What’s new? The experts from Netlab 360 reported a critical vulnerability in Apache Log4j, a Java-based logging library. The attackers used it to install the malware and hidden miners.
Information on the Netlab 360 blog
What is the danger of a critical vulnerability? Log4Shell or LogJam is a Remote Code Execution class vulnerability. If the attackers manage to exploit it on one of the servers, they will be able to execute the arbitrary code and take full control of the system. The hackers took advantage of the situation to launch the Kinsing crypto miners and organize large-scale DDoS attacks. .
What are the experts saying? The Apache Foundation recommends that all developers upgrade the library to version 2.15.0, or if this is not possible, use one of the methods described on the Apache Log4j Security Vulnerabilities page. The experts added:
“At the moment, there have been no instances of exploitation of vulnerabilities by ransomware or APT-groups, however, the fact of the deployment of Cobalt Strike beacons indicates the forthcoming malicious campaigns.”
Useful material?
Incidents
The Commission actively began winding down proceedings against crypto firms after a change in leadership in January
Mar 26, 2025
Market
The feature is available for selected clients
Mar 24, 2025
Incidents
He turned out to be a British citizen who had previously been convicted of fraud
Mar 21, 2025
Market
Transactions related to the new platform may also be blocked due to sanctions evasion
Mar 20, 2025
Market
To pass, the document must receive majority support in the House of Representatives and 60 votes in the Senate
Mar 14, 2025
Market
The update will gradually become available to users in March and April
Mar 13, 2025