HomeSecurityHackers attack Apache AXIS server

Hackers attack Apache AXIS server

Apache Axis provides the ability to add service interfaces to web applications. Recently, researchers at Binary Defense discovered that hackers are actively attacking the Apache AXIS server to deploy malicious web shells.

See also: Apache fixes critical vulnerability in OFBiz

Apache AXIS

Apache AXIS Server

In August 2024, a malicious actor linked to China compromised three unmanaged AIX servers that were accessible over the Internet, with the master passwords used to manage Apache Axis servers.

The attacker then proceeded to upload an AxisInvoker web shell , gain SSH access, and use a Fast Reverse Proxy (FRP) to permanently communicate with the targeted network.

See also: CISA points out critical flaw in Apache OFBiz

The malicious actors then switched to the Windows, where they attempted to inject Cobalt Strike and web shells crafted with JavaScript.

They carried out NTLM relay attacks to conduct Active Directory authentication and account impersonation.

Hackers attack Apache AXIS server

The attack on Apache Axis was contained when someone attempted to dump the LSASS process memory , which is a well-known technique for collecting credentials on a Windows server. Such an incident illustrates the dangers of shadow IT when IT solutions are implemented without the control of the security team.

It highlights the importance of advanced threat detection across the entire network, even including outdated systems, to prevent such a sophisticated attack that uses trivial and low-profile vectors.

See also: Apache vulnerability allows hackers to steal sensitive data from Unix systems

A malicious web shell is a script that hackers install on a compromised web server to gain and maintain access. These scripts are often written in languages ​​such as PHP, ASP, JSP , or Perl, allowing attackers to execute arbitrary commands remotely. Web shells are a favored tool among cybercriminals due to their ease of deployment and the broad control they provide over the compromised system. Once installed, a web shell can be used to perform a variety of malicious activities, such as stealing sensitive data, launching further attacks, or modifying existing web content.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS