Researchers Detail Campaign Using Brute-Force Attacks to Hijack Tomcat Servers

Summary
Aqua researchers detail a campaign that brute-forces Tomcat management consoles, installs JSP backdoors, steals SSH credentials, and deploys Windows and Linux payloads for persistence, lateral spread, and cryptomining.
Key points
- Attackers use a Python script to try common usernames and weak passwords against exposed Tomcat management consoles, then upload and execute JSP files.
- The JSP files act as a Java web shell and persistence mechanism, enabling encrypted payload execution and copies of the backdoor in multiple Tomcat directories.
- Windows and Linux payloads are deployed; the Linux script searches for SSH keys and hosts and uses them to spread within compromised networks.
- The packed Linux malware disguises itself as kernel processes, modifies startup files, and runs a cryptominer; researchers also observed anti-debugging behavior.
- The download domain dbliker.top disguises a payload behind a fake 404 page. The article lists it and several IP addresses as indicators of compromise.
- Aqua reports that runtime protection generated 16 incidents during the honeypot attack. Recommended defenses include restricting management interfaces, patching, limiting privileges, segmenting networks, and runtime monitoring.
Article Details
- Attack Vectors
- A Python script brute-forces the Tomcat management console using common usernames and weak passwords; the observed honeypot compromise followed successful credential guessing.
- Attackers upload two JSP web shells: one decrypts and executes supplied Java code, while the other downloads payloads and copies itself into multiple application directories for persistence.
- The downloader attempts to execute a Windows payload and falls back to a Linux shell-script delivery chain if execution fails.
- A Linux payload-delivery page displays a misleading 404 message while concealing an encoded shell payload inside its HTML.
- The ldr.sh script collects local SSH private keys and discovers hosts from SSH configuration, shell history, and known_hosts files, then attempts remote infection over SSH.
- Packed ELF payloads impersonate kernel processes, establish shell-profile persistence, and run cryptocurrency mining software. A modified secondary binary receives a different hash, complicating hash-based blocking.
- Defensive Notes
- Patch internet-facing applications promptly; the article specifically prioritizes CVE-2025-24813 as actively exploited, but the documented honeypot entry method was credential brute force.
- Disable unnecessary exposed services and disable or restrict Tomcat Manager and Host Manager interfaces using IP or host filtering.
- Restrict root access to critical files and directories and apply Role-Based Access Control.
- Segment critical servers and restrict outbound connections, particularly connections to cryptocurrency mining pools.
- Deploy runtime behavioral protection capable of detecting cryptomining, binary drift, binary deletion, unpacking, and kernel-process impersonation.
- The monitored honeypot generated 16 runtime incidents and 319 audit events. Researchers deliberately allowed execution to observe the attack rather than enforce blocking.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | auto[.]c3pool[.]org | Mining pool contacted by the cryptominer running on the compromised server. |
| DOMAIN | dbliker[.]top | Malicious script download domain identified in the narrative and IOC table. |
| DOMAIN | gulf[.]moneroocean[.]stream | Mining pool contacted by the cryptominer running on the compromised server. |
| IPV4 | 113[.]198[.]137[.]150 | Payload server used by the JSP downloader to retrieve the Windows os.s executable. |
| IPV4 | 138[.]201[.]247[.]154 | Download server identified in the article's IOC table. |
| IPV4 | 209[.]141[.]37[.]95 | Attacker IP identified in the IOC table as a Tor exit router. |
| IPV4 | 216[.]239[.]38[.]21 | Download server identified in the article's IOC table. |
| IPV4 | 68[.]183[.]238[.]15 | Download server identified in the article's IOC table. |
| MD5 | 5012b9d97848cafc2d5a55ea098c7d3c | Source-listed MD5 for an unpacked main payload. |
| MD5 | 5e2814800cbe66281511ae5dfa62a94e | Source-listed MD5 for a packed main payload. |
| MD5 | 713091980135a30a452b34026d949890 | Source-listed MD5 for the malicious ldr.sh shell script. |
| MD5 | 718edc4d574df0accd3ba7591a43eddf | Source-listed MD5 for a packed main payload. |
| MD5 | 8b3a077339cd75a313a531798852a352 | Source-listed MD5 for the malicious test.jsp script. |
| MD5 | bd8ce6bd59b1f648e0ac38e575780453 | Source-listed MD5 for Windows malware os.s.exe. |
| MD5 | d82a372d3f9ee28b34f0f8299d7a5132 | Source-listed MD5 for the malicious tomcat.jsp script. |
| MD5 | fd87e203c4867c688024175aeee0092f | Source-listed MD5 for an unpacked main payload. |
| MD5 | ff20fd3228162a71efa8c4b3786b4c3e | Source-listed MD5 for the malicious w.sh shell script. |
| URL | hxxp[:]//113[.]198[.]137[.]150:8080/os[.]s | Windows malware download URL embedded in the malicious JSP script. |
| URL | hxxps[:]//www[.]dbliker[.]top/w | Linux payload-delivery URL concealing an encoded shell payload behind a misleading 404 page. |
MITRE ATT&CK
T1018 · Remote System DiscoveryThe script discovers candidate remote hosts from SSH configurations, shell history, and known_hosts files.T1021.004 · SSHThe script attempts SSH connections using discovered users, hosts, and private keys to execute a remote infection command.T1027.002 · Software PackingThe main ELF payload is packed and expands from approximately 2.6 MB to 8.6 MB when unpacked.T1033 · System Owner/User DiscoveryThe scripts use whoami and id -u to identify the execution account and check for root privileges.T1036.005 · Match Legitimate Resource Name or LocationMalware processes masquerade as kernel processes using the names (sd-pam) and [cpuhp/0].T1059.003 · Windows Command ShellThe JSP payload invokes cmd /c to copy web shells and modify Windows file permissions.T1059.004 · Unix ShellThe Linux delivery chain invokes bash and sh to decode and execute downloaded scripts and infect remote hosts.T1070.004 · File DeletionThe payload deletes its original dropped binary, and the Linux command removes /var/tmp/sos after execution.T1105 · Ingress Tool TransferJSP and shell downloaders retrieve Windows executables, Linux scripts, and packed ELF payloads from remote servers.T1110.001 · Password GuessingA Python script tests common usernames and weak passwords against the Tomcat management console.T1140 · Deobfuscate/Decode Files or InformationThe Java loader decodes Base64 and decrypts AES-protected code; the Linux delivery command repeatedly decodes Base64 before execution.T1222.001 · Windows PermissionsThe Windows JSP script invokes Cacls to change access permissions on the Tomcat directory.T1222.002 · Linux and Mac PermissionsLinux commands make the dropped payload executable and change permissions on collected SSH private keys.T1496 · Resource HijackingThe final payload hijacks server resources for cryptocurrency mining and connects to mining pools.T1505.003 · Web ShellAttackers upload JSP web shells that execute arbitrary Java code and copy themselves into Tomcat application directories.T1546.004 · Unix Shell Configuration ModificationThe malware adds commands to shell profile files that launch its copied payload from /opt/.T1552.004 · Private KeysThe ldr.sh script searches for id_rsa files, PEM files, and private-key paths listed in SSH configurations.T1622 · Debugger EvasionResearchers observed anti-debugging behavior when executing the packed ELF under Strace.