Attackers exploited Log4Shell (CVE-2021-44228), a critical remote-code-execution vulnerability in Apache Log4j, to deploy ransomware, cryptocurrency miners, botnets and backdoors. ReliaQuest reported widespread scanning and exploitation after disclosure, citing Check Point’s observation of more than 1.2 million exploit attempts across customer deployments. Barracuda subsequently recorded relatively steady attack volumes over two months, with Mirai the most common identified payload alongside Monero miners and BillGates DDoS malware. Curated Intel analyzed ransomware delivered through a vulnerable Log4j2 system and tentatively attributed it to TellYouThePass; its downloader supported Linux and Windows payloads, and the ransom note demanded 0.05 BTC. Separately, 360Netlab discovered B1txor20 spreading through Log4j exploitation: an ARM/x64 Linux backdoor using DNS tunneling for command-and-control, with reverse-shell, proxying, exfiltration and rootkit-installation capabilities.
CISA and the FBI assessed that likely Iranian government-sponsored actors exploited an unpatched VMware Horizon server to compromise an unnamed federal civilian agency as early as February 2022. The intruders installed XMRig, harvested credentials with Mimikatz, created a rogue domain administrator account and moved laterally to the domain controller. They also weakened Windows Defender protections and deployed Ngrok reverse proxies to maintain access and tunnel RDP over outbound HTTPS. The incident demonstrated that Log4Shell exploitation could enable persistent enterprise compromise, not just opportunistic malware installation. Defenders should inventory embedded Log4j dependencies, upgrade affected software to supported patched versions and investigate exposed systems for compromise. CISA specifically urged organizations that had not promptly patched affected VMware systems to assume compromise, preserve forensic evidence before remediation, investigate lateral movement and strengthen identity controls, segmentation and credential protection.

See which actors are running it and whether you're in range.
19 events from the most recent confirmed update back to the earliest known activity.
CISA and the FBI published advisory AA22-320A on November 16, 2022, assessing that likely Iranian government-sponsored APT actors conducted the federal-network compromise. The advisory documented cryptocurrency mining, credential theft, lateral movement, and Ngrok persistence, and urged investigation of VMware systems that were not promptly patched.
CISA conducted an onsite incident response engagement from mid-June through mid-July 2022. Investigators determined that the compromise dated back to at least February 2022.
CISA identified suspected APT activity through retrospective analysis of EINSTEIN intrusion detection data in April 2022. Bidirectional traffic with Log4Shell-associated infrastructure and a successful suspected LDAP callback supported its assessment that the network was compromised.
A 360Netlab honeypot captured an unknown ELF executable propagating through the Log4j vulnerability on February 9, 2022, and a DNS-tunnel alert triggered investigation. Researchers named the Linux backdoor and botnet B1txor20.
Attackers exploited CVE-2021-44228 in an unpatched VMware Horizon server at an unnamed Federal Civilian Executive Branch organization. The initial exploit weakened Windows Defender protections and downloaded an archive containing XMRig-related files.
Barracuda's systems detected Log4Shell exploitation attempts beginning December 10, 2021. Attack volumes remained relatively steady over the following two months, with occasional spikes and dips.
The CVE-2021-44228 record was published, documenting arbitrary code execution through attacker-controlled JNDI endpoints in Apache Log4j2's log4j-core component. The record credits Chen Zhaojun of Alibaba Cloud Security Team with discovering the vulnerability.
VMware issued Log4Shell updates in December 2021. CISA and the FBI subsequently recommended assuming compromise of affected VMware Horizon systems that were not promptly patched or protected with workarounds.
The federal-network attackers attempted to dump LSASS memory using Task Manager. Additional antivirus software installed by the victim organization blocked the attempt.
The attackers used the rogue administrator account to access additional hosts, disable Windows Defender, and install Ngrok reverse proxies for persistent RDP access over HTTPS. They reached the domain controller, enumerated domain computers, and changed local administrator passwords to retain backup access.
After initial access, the attackers moved from the VMware Horizon server to a VDI-KMS host using RDP and the built-in DefaultAccount. They executed Mimikatz to harvest credentials and created a rogue domain administrator account.
360Netlab analyzed B1txor20 samples targeting ARM and x64 Linux systems and documented DNS-tunneled command-and-control protected with compression, RC4 encryption, and custom Base64 encoding. The malware supported command execution, reverse shells, SOCKS5 proxying, file access, and rootkit installation, although some functions were unused or defective.
Barracuda's analysis identified Monero miners, Mirai variants, BillGates DDoS malware, and a Java prank payload, with Mirai the most common identified payload. Researchers also observed VMware-targeting infection attempts, including a payload URLhaus identified as Mirai, without attributing those attempts to Conti.
On December 28, 2021, Apache released Log4j 2.17.1 for Java 8, 2.12.4 for Java 7, and 2.3.2 for Java 6 to address CVE-2021-44832. The vulnerability permits remote code execution but requires an attacker to have permission to modify a specific configuration file.
Researchers assessed that the ransomware likely belonged to TellYouThePass based on its ransom note, but the attribution was not definitive. They shared a Java downloader supporting Linux and Windows payload delivery from 158.247.216.148 and a ransom note demanding 0.05 BTC.
Curated Intel researchers reported ransomware deployment on a system exploited through Log4j2. The source did not identify the affected organization, a specific CVE, or the attack date.
ReliaQuest observed users on prominent dark-web forums exchanging Log4j attack methods and reposting proofs of concept. Some users were also exploring ways to bypass web application firewalls.
Check Point reported more than 1.2 million exploit attempts against customer deployments across all continents and most industries. It also reported more than 60 variants of the original exploit.
Apache researchers identified CVE-2021-45046 after finding that certain Log4j configurations remained vulnerable. ReliaQuest described it at the time as a denial-of-service vulnerability affecting versions from the 2.0 beta through 2.15 under certain conditions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 107 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcecisa.gov
Open sourceblog.netlab.360.com
Open sourceblog.barracuda.com
Open sourcecuratedintel.org
Open sourcereliaquest.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.