Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io

Made with 💙 by Wiz

Last Updated: April 3, 2025

Cloud Threat Landscape
/Incidents
Incidents
/
Lucifer Botnet targeting Hadoop

Lucifer Botnet targeting Hadoop

Type
Campaign
Actors
😈Lucifer operator
Pub. date
February 22, 2024
Initial access
1-day vulnerabilitySoftware misconfig
Impact
Denial of serviceResource hijacking
Observed techniques
Vulnerability exploitationMisconfigured Apache Hadoop abuse
Observed tools
Monero minerLuciferXMRig
Targeted technologies
Apache HadoopApache Druid
References
https://www.aquasec.com/blog/lucifer-ddos-botnet-malware-is-targeting-apache-big-data-stack/
Status
Finalized
Last edited
Jun 2, 2024 11:55 AM

Researchers identified a malicious campaign focusing on Apache big-data solutions, particularly Apache Hadoop and Apache Druid. This campaign leverages the Lucifer DDoS botnet, infecting Linux machines to mine the Monero cryptocurrency.

The attackers target misconfigurations and known vulnerabilities within Apache Hadoop and Apache Druid to initiate their attacks. Notable vulnerabilities include CVE-2021-25646 in Druid, allowing remote code execution.

The campaign uses the Lucifer malware to exploit these vulnerabilities, converting the infected Linux systems into bots for Monero cryptomining.

The campaign has evolved over six months, showing variations in the malware deployment strategy, including the use of droppers and cryptominers. The attackers also utilize defense evasion techniques and ensure persistence through scheduled tasks.