Spring4Shell Abused in Campaign Pushing Mirai
Summary
Both security companies noticed that a weaponized version of the Mirai malware, commonly associated with botnet use, was being used to actively exploit the Spring4Shell flaw. These include the presence of the Spring framework, running patches prior to 5.2.20 and the JDK updated to versions 9 or newer. The attacks deploying weaponized Mirai malware on systems vulnerable to Spring4Shell were mostly focused on targets located in Singapore and the region. Researchers are expecting attacks attempting to exploit the Spring4Shell vulnerability to only increase in volume over the next months, as the flaw has been documented well and the details are out there for threat actors to pick up on as well. In that sense, even 1% of unpatched systems out of millions is a significant number of potential targets for the exploit.