Friday, November 15, 2024
HomeCyber Security NewsHackers Attack Apache Tomcat Servers to Deploy Malware

Hackers Attack Apache Tomcat Servers to Deploy Malware

Published on

Apache Tomcat, a free and open-source server, supports Jakarta Servlet, Expression Language, and WebSocket technologies, providing a “pure Java” HTTP web server environment.

Apache Tomcat dominates with nearly 50% developer adoption, and it’s widely used in the following developments:-

  • Cloud
  • Big data
  • Website

Aqua’s cybersecurity researchers found a new campaign exploiting misconfigured Apache Tomcat servers to deliver Mirai botnet malware and cryptocurrency miners.

- Advertisement - SIEM as a Service

Technical analysis

Over two years, Aqua identified 800+ attacks on its Tomcat server honeypots, 96% linked to the Mirai botnet.

Among the attacks, 20% (152) used the “neww” web shell script, sourced from 24 IPs, and 68% came from 104.248.157[.]218.

IPs initiating the attack (Source – Aqua)

The threat actor launched a brute force attack against the scanned Tomcat servers to access the web application manager through various credential combinations.

After successful entry, threat actors deploy a WAR file with ‘cmd.jsp’ web shell, enabling remote command execution on the Tomcat server that is compromised.

The whole attack chain involves the “downloading and running” of “neww” shell script, which is then deleted using the “rm -rf” command. The script then fetches 12 binary files tailored to the attacked system’s architecture.

Attack Flow (Source – Aqua)

The WAR file holds essential files for web applications, including:-

  • HTML
  • CSS
  • Servlets
  • Classes

While all these elements efficiently streamline the web app deployment on compromised Tomcat servers.

The last-stage malware is a Mirai botnet variant, utilizing infected hosts for orchestrating distributed denial-of-service (DDoS) attacks.

Threat actor infiltrates web app manager with valid credentials, uploads disguised web shell in WAR file, executes commands remotely and initiates the attack.

The findings highlight cryptocurrency mining‘s lucrative growth, with a 399% increase and 332 million cryptojacking attacks globally in H1 2023.

Recommendation

Cybersecurity analysts recommended the following recommendations to mitigate such attacks:-

  • Make sure to configure all your environments properly.
  • Make sure to frequently scan your environments for unknown threats.
  • Empower your developers, DevOps, and security teams with cloud-native tools for scanning vulnerabilities and misconfigurations.
  • Make sure to use runtime detection and response solutions.

Keep yourself informed about the latest Cyber Security News by following us on GoogleNews, Linkedin, Twitter, and Facebook.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Critical Laravel Vulnerability CVE-2024-52301 Allows Unauthorized Access

CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for...

4M+ WordPress Websites to Attacks, Following Plugin Vulnerability

A critical vulnerability has been discovered in the popular "Really Simple Security" WordPress plugin,...

CISA Warns of Actors Exploiting Two Palo Alto Networks Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert and added...

Google Unveils New Intelligent, Real-Time Protections for Android Users

Google has once again raised the bar for mobile security by introducing two new...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Critical Laravel Vulnerability CVE-2024-52301 Allows Unauthorized Access

CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for...

4M+ WordPress Websites to Attacks, Following Plugin Vulnerability

A critical vulnerability has been discovered in the popular "Really Simple Security" WordPress plugin,...

CISA Warns of Actors Exploiting Two Palo Alto Networks Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert and added...