Hadooken Hits Hard: Cryptominer and DDoS Malware Targeting Oracle WebLogic Servers

Hadooken is wreaking havoc on Oracle WebLogic Servers, dropping cryptominers and DDoS malware. Named after the Street Fighter move, this malware is brute-forcing its way in and causing mayhem.

Pro Dashboard

Hot Take:

Looks like Oracle WebLogic Servers just got a taste of the old-school Street Fighter special move, but instead of a blue fireball, it’s raining down cryptominers and DDoS attacks. Hadooken! More like, “HadoOops, there goes your server.”

Key Points:

  • Aqua Nautilus identified the Hadooken malware on their WebLogic honeypot.
  • The threat actor used brute force to access the WebLogic admin panel.
  • Hadooken was deployed using Python and “c” shell scripts.
  • The malware includes a cryptominer and Tsunami DDoS components.
  • Potential future threats include ransomware capabilities.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?