Security researchers discovered that the critical Log4j Log4Shell vulnerability was used to download and install ransomware on a vulnerable system.

Last Friday, a public exploit was released for a critical zero-day vulnerability called “Log4Shell” located in the Apache Log4j Java-based logging platform.
See also: Log4j: Severe vulnerability hits the internet [UPDATE]
The Log4j vulnerability, officially known as CVE-2021-44228, allows malicious users to gain unauthorized access to computer systems and execute code remotely. Since it became known, it has caused serious problems in the global market, having already been used to carry out various attacks (cryptomining, installing cobalt strike beacons, installing malware, etc.).
The vulnerability was fixed in Log4j 2.15.0 and Log4j 2.16.0, but criminals are looking for systems that are still vulnerable.
Zero -day Log4j Log4Shell now used in ransomware attack
BitDefender researchers have now reported that they have detected the first ransomware installation directly via Log4Shell exploits . Previously, experts had not seen ransomware gangs exploit the Log4j Log4Shell vulnerability, although they had expected it, since the zero-day is already being used to install cobalt strike beacons.
The exploit downloads a Java class from hxxp://3.145.115[.]94/Main.class which is loaded and executed by the Log4j application.
After uploading, it downloads a .NET binary from the same server to install the new ransomware [VirusTotal] named “Khonsari“.
See also: Google: Fixes zero-day bug with emergency Chrome update
The same name is also used as an extension on encrypted files and in the ransom note:

BitDefender also observed that this threat actor was using the same server to distribute the Orcus Remote Access Trojan.
Wiper?
Ransomware expert Michael Gillespietold BleepingComputer that if someone gets infected with Khonsari, they won't be able to recover their data for free. However, something strange is happening. The ransom note doesn't appear to include any actual contact information for the attacker to pay the ransom. An Emsisoft analyst told BleepingComputer that the information doesn't belong to any gang.
See also: Moobot botnet spreads via vulnerability in Hikvision cameras
According to BleepingComputer, this could mean that it is a wiper (and not ransomware), which aims to destroy the victim's files.
Even if it's not ransomware, it's only a matter of time before the Log4j Log4Shell vulnerability is exploited to carry out such an attack.
Source: Bleeping Computer
