Menu

Post image 1
Post image 2
Post image 3
Post image 4
Post image 5
Post image 6
Post image 7
Post image 8
Post image 9
Post image 10
Post image 11
Post image 12
Post image 13
1 / 13
0

Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal

Akamai·Ori David·about 1 month ago
#mpdlDWZ0
Reading 0:00
15s threshold

Blog Security Research Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal Ori David is a Security Researcher at Akamai. His research is focused on offensive security, malware analysis, and threat hunting.  Editorial and additional commentary by Tricia Howard Executive summary \r\n The Akamai Security Intelligence Group (SIG) has uncovered details about a new variant of the FritzFrog botnet, which abuses the 2021 Log4Shell vulnerability. \r\n \r\n Over the years we have seen more than 20,000 FritzFrog attacks, and 1,500+ victims. \r\n \r\n The malware infects internet-facing servers by brute forcing weak SSH credentials. Newer variants now read several system files on compromised hosts to detect potential targets for this attack that have a high likelihood of being vulnerable. \r\n \r\n The vulnerability is exploited in a brute-force manner that attempts to target as many vulnerable Java applications as possible.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More