The worm has been circulating for a couple of days at least, and it s not clear right now how many servers have been compromised or what the origins of it are. It apparently exploits an old vulnerability in the JBoss Application Server, which was patched in April 2010. The worm also attempts to install a remote access tool in order to give the attacker control over the newly infected server. Officials at Red Hat, which provides paid support for the open-source JBoss software, said that the vulnerability the worm exploits has been patched for more than a year.
Source: https://threatpost.com/jboss-worm-exploiting-old-bug-infect-unpatched-servers-102111/75784/

