Cybersecurity firm CrowdStrike has discovered an attempt by a China-based group to infiltrate an academic institution via the Log4j vulnerability. CrowdStrike dubbed the group “Aquatic Panda” and said it is a “dual-mission intelligence-gathering and industrial espionage group” that has been operating since at least May 2020.
See also: CISA: Apache Log4j scanner released to detect vulnerable apps

The exact intent of the group is unknown because the attack was stopped. CrowdStrike told ZDNet, however, that Aquatic Panda is known to persist across environments to gain access to intellectual property and other industrial trade secrets.
According to CrowdStrike, their system revealed “suspicious activity originating from a Tomcat process running under a vulnerable VMWare Horizon instance at a large academic institution, leading to the disruption of an active hands-on intrusion.”.
See also: NVIDIA: Reveals the products affected by the Log4j bug
After monitoring the group's operation and reviewing available telemetry, CrowdStrike said it believes a modified version of the Log4j exploit was likely used.

The CrowdStrike team discovered that Aquatic Panda used a public GitHub project from December 13, 2021, to gain access to the vulnerable VMWare Horizon instance.
CrowdStrike officials told ZDNet that they are seeing various threat actors both inside and outside of China exploiting the Log4J vulnerability.
Last week, the US, UK, Australia and other countries issued an advisory on Log4j in response to "active exploitation by multiple threat actors, including malicious cyber actors.".
See also: Log4j Log4Shell vulnerability used to install Dridex banking trojan
Multiple groups from North Korea, Iran, Turkey, and China are exploiting the vulnerability along with a number of ransomware and cybercriminal organizations.
CISA Director Jen Easterly said that the Log4j vulnerabilities pose a serious and ongoing threat to organizations and governments around the world.
Information source: zdnet.com
