{"id":2577,"date":"2024-02-21T22:48:40","date_gmt":"2024-02-21T22:48:40","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/lucifer-botnet-heat-apache-hadoop-servers"},"modified":"2024-02-21T22:48:40","modified_gmt":"2024-02-21T22:48:40","slug":"lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/02\/21\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers\/","title":{"rendered":"&#8216;Lucifer&#8217; Botnet Turns Up the Heat on Apache Hadoop Servers"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltb8e08c928932e2d3\/65d6794705c1da040a7f93ba\/lava_fire-Cultura_Creative_Ltd-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A threat actor is targeting organizations running Apache Hadoop and Apache Druid big data technologies with a new version of the Lucifer botnet, a known malware tool that combines cryptojacking and distributed denial of service (DDoS) capabilities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The campaign is a departure for the botnet, and an analysis this week from Aqua Nautilus suggests that its operators are testing new infection routines as a precursor to a broader campaign.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Lucifer is self-propagating malware that researchers at Palo Alto Networks first reported in May 2020. At the time, the company described the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/lucifer-malware-aims-to-become-broad-platform-for-attacks\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">threat as dangerous hybrid malware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that an attacker could use to enable DDoS attacks, or for dropping XMRig for mining Monero cryptocurrency. Palo Alto said it had <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/lucifer-new-cryptojacking-and-ddos-hybrid-malware\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">observed attackers also using Lucifer<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to drop the NSA&#8217;s leaked <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/eternalblue-longevity-underscores-patching-problem\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">EternalBlue, EternalRomance, and DoublePulsar<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> malware and exploits on target systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Lucifer&nbsp;is a new hybrid of cryptojacking and DDoS malware variant that leverages old vulnerabilities to spread and perform malicious activities on Windows platforms,&#8221; Palo Alto had warned at the time.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Now, it&#8217;s back and targeting Apache servers. Researchers from Aqua Nautilus who have been monitoring the campaign <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.aquasec.com\/blog\/lucifer-ddos-botnet-malware-is-targeting-apache-big-data-stack\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">said in a blog this week<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> they had counted more than 3,000 unique attacks targeting the company&#8217;s Apache Hadoop, Apache Druid, and Apache Flink honeypots in just the last month alone.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Lucifer's 3 Unique Attack Phases\">Lucifer&#8217;s 3 Unique Attack Phases<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The campaign has been ongoing for at least six months, during which time the attackers have been attempting to exploit known misconfigurations and vulnerabilities in the open source platforms to deliver their payload.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The campaign so far has been comprised of three distinct phases, which the researchers said is likely an indication that the adversary is testing defense evasion techniques before a full-scale attack.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The campaign began targeting our honeypots in July,&#8221; says Nitzan Yaakov, security data analyst at Aqua Nautilus. &#8220;During our investigation, we observed the attacker updating techniques and methods to achieve the main goal of the attack \u2014 mining cryptocurrency.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">During the first stage of the new campaign, Aqua researchers observed the attackers scanning the Internet for misconfigured Hadoop instances. When they detected a misconfigured Hadoop YARN (Yet Another Resource Negotiator) cluster resource management and job scheduler technology on Aqua&#8217;s honeypot, they targeted that instance for exploit activity. The misconfigured instance on Aqua&#8217;s honeypot had to do with Hadoop YARN&#8217;s resource manager and gave the attackers a way to execute arbitrary code on it via a specially crafted HTTP request.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attackers exploited the misconfiguration to download Lucifer, execute it and store it to the Hadoop YARN instance&#8217;s local directory. They then ensured the malware was executed on a scheduled basis to ensure persistence. Aqua also observed the attacker deleting the binary from the path where it was initially saved to try and evade detection.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the second phase of attacks, the threat actors once again targeted misconfigurations in the Hadoop big-data stack to try and gain initial access. This time, however, instead of dropping a single binary, the attackers dropped two on the compromised system \u2014 one which executed Lucifer and the other which apparently did nothing.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the third phase, the attacker switched tactics and, instead of targeting misconfigured Apache Hadoop instances, began looking for vulnerable Apache Druid hosts instead. Aqua&#8217;s version of the Apache Druid service on its honeypot was unpatched against <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-25646\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">CVE-2021-25646<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a command injection vulnerability in certain versions of the high-performance analytics database. The vulnerability gives authenticated attackers a way to execute user-defined JavaScript code on affected systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attacker exploited the flaw to inject a command for downloading two binaries and enabling them with read, write, and execute permissions for all users, Aqua said. One of the binaries initiated the download of Lucifer, while the other executed the malware. In this phase, the attacker&#8217;s decision to split the downloading and execution of Lucifer between two binary files appears to have been an attempt to bypass detection mechanisms, the security vendor noted.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"How to Avoid a Hellish Cyberattack on Apache Big Data\">How to Avoid a Hellish Cyberattack on Apache Big Data<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ahead of a potential coming wave of attacks against Apache instances, enterprises should review their footprints for common misconfigurations, and ensure all patching is up-to-date.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Beyond that, the researchers noted that &#8220;unknown threats can be identified by scanning your environments with runtime detection and response solutions, which can detect exceptional behavior and alert about it,&#8221; and that &#8220;it is important to be cautious and aware of existing threats while using open-source libraries. Every library and code should be downloaded from a verified distributor.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/lucifer-botnet-heat-apache-hadoop-servers\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A threat actor is targeting organizations running Apache Hadoop and<\/p>\n","protected":false},"author":12,"featured_media":2578,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2577","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?fit=2560%2C1707&ssl=1",2560,1707,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?fit=2048%2C1365&ssl=1",2048,1365,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/lucifer-botnet-turns-up-the-heat-on-apache-hadoop-servers-scaled.jpg?fit=2560%2C1707&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2577"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2577\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2578"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}