Blog | G5 Cyber Security

Log4j vulnerability now used to install Dridex banking malware

Threat actors now exploit the critical Apache Log4j vulnerability named Log4Shell to infect vulnerable devices with the notorious Dridex banking trojan or Meterpreter. The Log4J vulnerability is now exploited to infect Windows and Linux devices with malware that can be used to install DrideX and MeterPreter. Threat actors are known for using racial and religious slurs in their file names and URLs, which BleepingComputer has redacted from the images below. The threat actors use the Log 4j RMI (Remote Method Invocation) exploit variant to force vulnerable devices to load and execute a Java class from an attacker-controlled remote server.”]

Source: https://www.bleepingcomputer.com/news/security/log4j-vulnerability-now-used-to-install-dridex-banking-malware/

Exit mobile version