HomeSecurityMirai malware now delivered using Spring4Shell exploits

Mirai malware now delivered using Spring4Shell exploits

The Mirai malware now leverages the Spring4Shell exploit to infect vulnerable web servers and recruit them for DDoS (distributed denial of service) attacks.

Zyxel

See also: Google: New policy changes strengthen Android security

Spring4Shell is a critical remote code execution (RCE) vulnerability tracked as CVE-2022-22965, affecting the Spring Framework, a widely used enterprise-level Java application development platform

Spring released emergency updates to fix the zero-day flaw a few days after its discovery, but exploitation of vulnerable installations by threat actors was already underway.

While Microsoft and CheckPoint have identified several attacks that exploit Spring4Shell, their success has been questionable as there have been no reports of large-scale incidents involving the vulnerability.

Therefore, Trend Micro's discovery of a Mirai botnet variant that successfully uses CVE-2022-22965 to promote its malicious operation is cause for concern.

See also: Microsoft: Prevented attacks against Ukraine by removing domains of Russian APT28

Mirai

To make matters worse, the leak of Mirai's source code in October 2016 spawned numerous variants such as Okiru, Satori, Masuta, and Reaper, making it an ever-mutating threat.

In January, cybersecurity firm CrowdStrike noted that malware targeting Linux systems increased by 35% in 2021 compared to 2020, with the XOR DDoS, Mirai, and Mozi malware families accounting for more than 22% of Linux-targeting threats detected during the year.

"The primary purpose of these malware families is to compromise vulnerable Internet-connected devices, gather them into botnets, and use them to execute distributed denial-of-service (DDoS) attacks," the researchers said.

The attacks were focused on Singapore

The active exploitation, which began a few days ago, is focused on vulnerable web servers in Singapore, which could be a preliminary testing phase before the threat actor scales the operation globally.

Spring4Shell is used to register a JSP web shell in the webroot of the web server via a specially crafted request, which threat actors can use to execute commands on the server remotely.

See also: The Works chain closes stores after cyberattack

In this case, threat actors use their remote access to download Mirai to the “/tmp” folder and execute it.

Spring4Shell

Hackers retrieve multiple Mirai samples for various CPU architectures and execute them with the “wget.sh” script.

Mirai Spring4Shell

Those that do not execute successfully due to their incompatibility with the targeted architecture are deleted from disk after the initial execution stage.

From Log4Shell to Spring4Shell

Various Mirai botnets were among the few persistent exploiters of the Log4Shell vulnerability (CVE-2021-44228) until last month, exploiting the flaw in the widely used Log4j software to recruit vulnerable devices into the DDoS botnet.

It is possible that botnet operators will now turn to experimenting with other potentially impactful flaws, such as Spring4Shell, to exploit new groups of devices.

Considering that these types of attacks could lead to ransomware deployments and data breaches, the case of Mirai resource hijacking for denial of service or crypto-mining seems relatively harmless.

As system patching continues and the number of vulnerable deployments decreases, unpatched servers will appear in more malicious network scans, leading to exploitation attempts.

Administrators should upgrade to Spring Framework 5.3.18 and 5.2.20 as soon as possible, as well as Spring Boot 2.5.12 or later, to close the door to these attacks before the most dangerous threat groups join the exploit effort.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS