Apache Struts 2 Exploit Being Used By Cyber Criminals For Crypto Mining Campaigns
A critical vulnerability has been found in Apache Struts 2 with a PoC for the flaw having been published on the internet. The flaw was patched by the Apache Software Foundation and tracked as CVE-2o18-11776. The vulnerability occurred due to insufficient validation of user data that was untrusted by the Struts framework, this flaw can lead to a Remote Code Execution.
Did The Apache Foundation Fix the Issue?
The Apache Foundation has released an updated build which protects servers from this attack, sadly if administrators have not yet applied the security patch they might find themselves being a part of a crypto jacking campaign which uses the aforementioned security flaw.
While mining cryptocurrency such as BTC, ETH and Monero is a completely legitimate activity, however if the power is taken without consent from a user, then these activities are known as crypto jacking, which is probably the most common strategy used by the hackers.
Attacks that are taking advantage of this Vulnerability
There is also an attack that takes advantage of this to exploit called CroniX which sends multiple HTTP requests whilst at the same time injecting an Object-Graph Navigation Language (OGNL) which contains malicious JavaScript Code. The code executes and downloads an additional file which launches a PowerShell command on the infected system.
The downloaded malicious script starts in memory which prepares the mining operation. There are also Cron jobs that are set for persistence. The malware also scans and deletes any binaries that are related to previous crypto miners.
"Considering it's only been two weeks since this vulnerability was found, it's worth noting how fast attackers are weaponizing vulnerabilities and how quickly researchers are seeing them in the wild," F5 Labs says. "Enterprises need be as vigilant as ever about patching affected systems immediately."Take your time to comment on this article.
Posted from my blog with SteemPress : https://latesthackingnews.com/2018/09/06/apache-struts-2-exploit-being-used-by-cyber-criminals-for-crypto-mining-campaigns/
Leave Apache Struts 2 Exploit Being Used By Cyber Criminals For Crypto Mining Campaigns to:
Read more #affectedbycryptomining posts
Best Posts From twr
We have not curated any of twr's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.
More Posts From twr
- Will a VPN Protect Me From a Data Breach?
- Why DDoS Attacks Are Still One of the Biggest Cyberthreats
- Why Do Subdomain Lookups for Cybersecurity?
- What You Need To Know About Bitcoin Before Investing Your Money In It
- Massive Cyberattacks that Shook the World in 2020
- Data of 176 Million Pakistani Citizens Found For Sale On Dark Web
- Apple Patched Three Zero-Days With The Release Of iOS 14.4
- Watch Out For This Wormable Malware Spreading Via WhatsApp
- What Password Managers Are Safe to Use in 2021
- 7 Reasons to Choose an Outsourced Security Services Provider