Hadooken Strikes: New Linux Malware Mines Crypto and Wreaks Havoc on Servers
Cybersecurity researchers have found new malware targeting Linux environments for illicit cryptocurrency mining. The malware, named Hadooken, exploits Oracle Weblogic server vulnerabilities to drop a crypto miner and DDoS botnet.

Hot Take:
Linux users, brace yourselves! The Hadooken malware is here to mine your crypto and eat your bandwidth. It’s like that annoying roommate who never pays rent and eats all your snacks, but in server form.
Key Points:
- Hadooken malware targets Linux environments, specifically Oracle Weblogic servers.
- The malware campaign involves dropping Tsunami malware and deploying a cryptocurrency miner.
- Attackers exploit known vulnerabilities and weak credentials to gain access.
- Hadooken spreads laterally within networks using SSH data and persists via cron jobs.
- Linked to bulletproof hosting providers in Russia, highlighting the cybercrime ecosystem.
Already a member? Log in here