Researchers Detail Campaign Using Brute-Force Attacks to Hijack Tomcat Servers

· Original article ↗

Summary

Aqua researchers detail a campaign that brute-forces Tomcat management consoles, installs JSP backdoors, steals SSH credentials, and deploys Windows and Linux payloads for persistence, lateral spread, and cryptomining.

Key points

  • Attackers use a Python script to try common usernames and weak passwords against exposed Tomcat management consoles, then upload and execute JSP files.
  • The JSP files act as a Java web shell and persistence mechanism, enabling encrypted payload execution and copies of the backdoor in multiple Tomcat directories.
  • Windows and Linux payloads are deployed; the Linux script searches for SSH keys and hosts and uses them to spread within compromised networks.
  • The packed Linux malware disguises itself as kernel processes, modifies startup files, and runs a cryptominer; researchers also observed anti-debugging behavior.
  • The download domain dbliker.top disguises a payload behind a fake 404 page. The article lists it and several IP addresses as indicators of compromise.
  • Aqua reports that runtime protection generated 16 incidents during the honeypot attack. Recommended defenses include restricting management interfaces, patching, limiting privileges, segmenting networks, and runtime monitoring.

Article Details

Attack Vectors
  • A Python script brute-forces the Tomcat management console using common usernames and weak passwords; the observed honeypot compromise followed successful credential guessing.
  • Attackers upload two JSP web shells: one decrypts and executes supplied Java code, while the other downloads payloads and copies itself into multiple application directories for persistence.
  • The downloader attempts to execute a Windows payload and falls back to a Linux shell-script delivery chain if execution fails.
  • A Linux payload-delivery page displays a misleading 404 message while concealing an encoded shell payload inside its HTML.
  • The ldr.sh script collects local SSH private keys and discovers hosts from SSH configuration, shell history, and known_hosts files, then attempts remote infection over SSH.
  • Packed ELF payloads impersonate kernel processes, establish shell-profile persistence, and run cryptocurrency mining software. A modified secondary binary receives a different hash, complicating hash-based blocking.
Defensive Notes
  • Patch internet-facing applications promptly; the article specifically prioritizes CVE-2025-24813 as actively exploited, but the documented honeypot entry method was credential brute force.
  • Disable unnecessary exposed services and disable or restrict Tomcat Manager and Host Manager interfaces using IP or host filtering.
  • Restrict root access to critical files and directories and apply Role-Based Access Control.
  • Segment critical servers and restrict outbound connections, particularly connections to cryptocurrency mining pools.
  • Deploy runtime behavioral protection capable of detecting cryptomining, binary drift, binary deletion, unpacking, and kernel-process impersonation.
  • The monitored honeypot generated 16 runtime incidents and 319 audit events. Researchers deliberately allowed execution to observe the attack rather than enforce blocking.

Indicators of compromise

TypeIndicatorContext
DOMAINauto[.]c3pool[.]orgMining pool contacted by the cryptominer running on the compromised server.
DOMAINdbliker[.]topMalicious script download domain identified in the narrative and IOC table.
DOMAINgulf[.]moneroocean[.]streamMining pool contacted by the cryptominer running on the compromised server.
IPV4113[.]198[.]137[.]150Payload server used by the JSP downloader to retrieve the Windows os.s executable.
IPV4138[.]201[.]247[.]154Download server identified in the article's IOC table.
IPV4209[.]141[.]37[.]95Attacker IP identified in the IOC table as a Tor exit router.
IPV4216[.]239[.]38[.]21Download server identified in the article's IOC table.
IPV468[.]183[.]238[.]15Download server identified in the article's IOC table.
MD55012b9d97848cafc2d5a55ea098c7d3cSource-listed MD5 for an unpacked main payload.
MD55e2814800cbe66281511ae5dfa62a94eSource-listed MD5 for a packed main payload.
MD5713091980135a30a452b34026d949890Source-listed MD5 for the malicious ldr.sh shell script.
MD5718edc4d574df0accd3ba7591a43eddfSource-listed MD5 for a packed main payload.
MD58b3a077339cd75a313a531798852a352Source-listed MD5 for the malicious test.jsp script.
MD5bd8ce6bd59b1f648e0ac38e575780453Source-listed MD5 for Windows malware os.s.exe.
MD5d82a372d3f9ee28b34f0f8299d7a5132Source-listed MD5 for the malicious tomcat.jsp script.
MD5fd87e203c4867c688024175aeee0092fSource-listed MD5 for an unpacked main payload.
MD5ff20fd3228162a71efa8c4b3786b4c3eSource-listed MD5 for the malicious w.sh shell script.
URLhxxp[:]//113[.]198[.]137[.]150:8080/os[.]sWindows malware download URL embedded in the malicious JSP script.
URLhxxps[:]//www[.]dbliker[.]top/wLinux payload-delivery URL concealing an encoded shell payload behind a misleading 404 page.

MITRE ATT&CK

T1018 · Remote System DiscoveryThe script discovers candidate remote hosts from SSH configurations, shell history, and known_hosts files.T1021.004 · SSHThe script attempts SSH connections using discovered users, hosts, and private keys to execute a remote infection command.T1027.002 · Software PackingThe main ELF payload is packed and expands from approximately 2.6 MB to 8.6 MB when unpacked.T1033 · System Owner/User DiscoveryThe scripts use whoami and id -u to identify the execution account and check for root privileges.T1036.005 · Match Legitimate Resource Name or LocationMalware processes masquerade as kernel processes using the names (sd-pam) and [cpuhp/0].T1059.003 · Windows Command ShellThe JSP payload invokes cmd /c to copy web shells and modify Windows file permissions.T1059.004 · Unix ShellThe Linux delivery chain invokes bash and sh to decode and execute downloaded scripts and infect remote hosts.T1070.004 · File DeletionThe payload deletes its original dropped binary, and the Linux command removes /var/tmp/sos after execution.T1105 · Ingress Tool TransferJSP and shell downloaders retrieve Windows executables, Linux scripts, and packed ELF payloads from remote servers.T1110.001 · Password GuessingA Python script tests common usernames and weak passwords against the Tomcat management console.T1140 · Deobfuscate/Decode Files or InformationThe Java loader decodes Base64 and decrypts AES-protected code; the Linux delivery command repeatedly decodes Base64 before execution.T1222.001 · Windows PermissionsThe Windows JSP script invokes Cacls to change access permissions on the Tomcat directory.T1222.002 · Linux and Mac PermissionsLinux commands make the dropped payload executable and change permissions on collected SSH private keys.T1496 · Resource HijackingThe final payload hijacks server resources for cryptocurrency mining and connects to mining pools.T1505.003 · Web ShellAttackers upload JSP web shells that execute arbitrary Java code and copy themselves into Tomcat application directories.T1546.004 · Unix Shell Configuration ModificationThe malware adds commands to shell profile files that launch its copied payload from /opt/.T1552.004 · Private KeysThe ldr.sh script searches for id_rsa files, PEM files, and private-key paths listed in SSH configurations.T1622 · Debugger EvasionResearchers observed anti-debugging behavior when executing the packed ELF under Strace.

CVE

Threat Actors

Malware

Vendors

Products

Tools

Related Articles