Threat actors and security researchers scan and exploit the Log4j Log4Shell vulnerability to develop malware or find vulnerable servers.
On Friday, an exploit was publicly released for a critical zero-day vulnerability called “Log4Shell” in the Apache Log4j Java-based logging platform. This vulnerability allows attackers to remotely execute a command on a vulnerable server.
See also: Grafana: Fixes zero-day vulnerability after it spread on Twitter

Shortly thereafter, Log4j 2.15.0 to fix the vulnerability, but threat actors had already begun scanning and exploiting vulnerable servers to steal data, install malware, or take control of a server.
Since this software is used in thousands of corporate applications and websites, experts believe that there could be many attacks and malware infections.
Let's look at the attacks that have already become known and exploit the Log4Shell vulnerability:
Log4Shell vulnerability used to install malware
When a vulnerability is discovered that allows remote code execution, attackers distributing malware are usually the first to begin exploiting it.
See below the known malware payloads that exploit Log4Shell:
Cryptominers
After the vulnerability was made public, cybercriminals began exploiting the Log4Shell vulnerability to execute shell scripts that download and install various cryptominers.
The threat actors behind the Kinsing backdoor and cryptomining botnet heavily exploit the Log4j vulnerability to execute shell scripts.
See also: Moobot botnet spreads via vulnerability in Hikvision cameras
This shell script will remove competing malware from the vulnerable device and then download and install the Kinsing malware, which will begin cryptomining.

Mirai and Muhstik botnets
Security researchers have also seen threat actors exploit the vulnerability to install Mirai and Muhstik malware on vulnerable devices.
These malware infect IoT devices and servers and add them to botnets . They then use them to deploy cryptominers and carry out large-scale DDoS attacks.
Cobalt Strike Beacons
The Microsoft Threat Intelligence Center reported that the Log4Shell vulnerability is also being used to install Cobalt Strike beacons on vulnerable devices.
Cobalt Strike is a legitimate penetration testing toolkit, which is used for remote network surveillance or execution of further commands.
However, cybercriminals commonly use cracked versions of Cobalt Strike in network breaches and ransomware attacks.
See also: Emotet installs Cobalt Strike on devices allowing for faster ransomware infection
Scanning and revealing information
In addition to using Log4Shell exploits to install malware, threat actors use the exploit to detect vulnerable servers and steal information.

Ransomware?
There is currently no evidence of ransomware. However, once Cobalt Strike is installed, it is only a matter of time before ransomware attacks are carried out.
Therefore, it is imperative to immediately install the latest version of Log4j to address the vulnerability.
Source: Bleeping Computer
