Thursday, April 10, 2025
HomeCVE/vulnerabilityNew DDoS malware Attacking Apache big-data stack, Hadoop, & Druid Servers

New DDoS malware Attacking Apache big-data stack, Hadoop, & Druid Servers

Published on

SIEM as a Service

Follow Us on Google News

Concerning a development for organizations leveraging Apache’s big-data solutions, a new variant of the Lucifer DDoS botnet malware targeting Apache Hadoop and Apache Druid servers has been identified.

This sophisticated malware campaign exploits existing vulnerabilities and misconfigurations within these systems to execute malicious activities, including cryptojacking and distributed denial-of-service (DDoS) attacks.

Document
Live Account Takeover Attack Simulation

How do Hackers Bypass 2FA?

Live attack simulation Webinar demonstrates various ways in which account takeover can happen and practices to protect your websites and APIs against ATO attacks.

- Advertisement - Google News

Exploiting Vulnerabilities and Misconfigurations

The Lucifer malware targets misconfigurations and known vulnerabilities within Apache Hadoop and Apache Druid environments, according to the Aquasec report.

One of the critical vulnerabilities exploited is CVE-2021-25646, a command injection vulnerability in Apache Druid that allows authenticated attackers to execute arbitrary code. 

Attack flow, initial phase
Attack flow, initial phase

By exploiting these weaknesses, attackers gain unauthorized access to the systems, enabling them to carry out their nefarious activities.

Combining Cryptojacking and DDoS Attacks

Combining cryptojacking and DDoS capabilities, its hybrid nature sets the Lucifer malware apart.

Once the malware gains a foothold, it transforms vulnerable Linux servers into Monero cryptomining bots.

 HTTP request of Apache Hadoop misconfiguration
 HTTP request of Apache Hadoop misconfiguration

Additionally, the malware can initiate DDoS attacks, further compromising the integrity and availability of the targeted servers.

The Lucifer Campaign: A Closer Look

Highlighted command of the misconfiguration in Apache Hadoop YARN
Highlighted command of the misconfiguration in Apache Hadoop YARN
  • The campaign operates in distinct phases, showcasing evolving attacker tactics.
  • Initial focus on exploiting misconfigured Hadoop servers.
  • The malware deployment strategy involved dropping two binary files on the compromised server, with one executing the malware.
  • Shifted focus to Apache Druid servers, exploiting the CVE-2021-25646 vulnerability to download and execute the Lucifer malware.
  • Highlights attackers’ adaptability and persistence.
  • Emphasizes the importance of maintaining robust security measures.
  • Advises organizations to review Apache Hadoop and Druid configurations for common misconfigurations.
  • Recommends ensuring all systems are patched and up-to-date to mitigate the risk of such attacks.

Implications and Recommendations

The emergence of the Lucifer malware targeting Apache’s big-data stack serves as a stark reminder of the ever-present cyber threats facing organizations.

With over 3,000 unique attacks detected in just the past month, the urgency for heightened security measures cannot be overstated. 

Organizations must proactively scan their environments for vulnerabilities, apply necessary patches, and employ runtime detection to identify and thwart unknown threats.

As the cyber threat landscape evolves, staying informed and vigilant is paramount.

The Lucifer DDoS botnet malware campaign targeting Apache Hadoop and Apache Druid servers exemplifies attackers’ sophisticated tactics to exploit vulnerabilities and misconfigurations for malicious gain.

Organizations can safeguard their critical infrastructure against such insidious threats by adopting comprehensive security strategies.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

PAN-OS DoS Vulnerability Allows Attackers to Force Repeated Firewall Reboots

A newly disclosed denial-of-service (DoS) vulnerability in Palo Alto Networks’ PAN-OS software enables attackers...

Linux Firewall IPFire 2.29 Launches with Post-Quantum Encryption and System Enhancements

The open-source Linux firewall solution, IPFire, has officially released its latest version, IPFire 2.29 - Core...

‘RemoteMonologue’ New Red Team Technique Exploits DCOM To Steal NTLM Credentials Remotely

A sophisticated new red team technique dubbed "RemoteMonologue" has emerged, enabling attackers to remotely...

OpenSSH 10.0 Released: New Protocol Changes and Key Security Improvements

The OpenSSH team has announced the release of OpenSSH 10.0 on April 9, marking an important...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

PAN-OS DoS Vulnerability Allows Attackers to Force Repeated Firewall Reboots

A newly disclosed denial-of-service (DoS) vulnerability in Palo Alto Networks’ PAN-OS software enables attackers...

Linux Firewall IPFire 2.29 Launches with Post-Quantum Encryption and System Enhancements

The open-source Linux firewall solution, IPFire, has officially released its latest version, IPFire 2.29 - Core...

‘RemoteMonologue’ New Red Team Technique Exploits DCOM To Steal NTLM Credentials Remotely

A sophisticated new red team technique dubbed "RemoteMonologue" has emerged, enabling attackers to remotely...