Hadooken Hits Hard: Cryptominer and DDoS Malware Targeting Oracle WebLogic Servers

Hadooken is wreaking havoc on Oracle WebLogic Servers, dropping cryptominers and DDoS malware. Named after the Street Fighter move, this malware is brute-forcing its way in and causing mayhem.

Hot Take:

Looks like Oracle WebLogic Servers just got a taste of the old-school Street Fighter special move, but instead of a blue fireball, it’s raining down cryptominers and DDoS attacks. Hadooken! More like, “HadoOops, there goes your server.”

Key Points:

  • Aqua Nautilus identified the Hadooken malware on their WebLogic honeypot.
  • The threat actor used brute force to access the WebLogic admin panel.
  • Hadooken was deployed using Python and “c” shell scripts.
  • The malware includes a cryptominer and Tsunami DDoS components.
  • Potential future threats include ransomware capabilities.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here