Ransomware groups have started posting successful exploits on a number forums and chats
While they are doing recon they are literally tossing up cryptominers so they maximizing profits.
Many of them are also not deploying RCE as a vector.
Many of them are grabbing server variables in order to maximize effectiveness and efficiency against targets.
Customized exploitation and info stealing are abound.
Very important: just watched attackers attempt to manually 'patch' an exploited box once they were in: smart move.
This ensures that no one else compromises the box post exploit (ie code red vs code blue days) and for admins to overlook VA scan results as false negatives.
Yikes
I've seen some what appears to be Mirai payloads across the wires, seems like some group of attackers have found some vulnerable IoT devices and are wget/curling those targets.
Expect some DDoS services to spring up and be very prevalent in the next couple of weeks
One of the groups is targeting a network packet inspecting appliances that uses elastic & logstash.
Literally the devices attempting to monitor and find vulns & security issues *in your own network* are now being compromised by sprewing traffic in subnets with log4j sploit spam
Also bypasses for WAFs are flying around too:
Seem some similar to this as well as other variants:
#Log4J based on what I've seen, there is evidence that a worm will be developed for this in the next 24 to 48 hours.
Self propagating with the ability to stand up a self hosted server on compromised endpoints.
In addition to spraying traffic, dropping files, it will have c2c
Biggest hurdle appears to be implementing a JDK gadget to enable code execution on limited env.
That is currently being researched by several groups.
Honestly I'm kinda surprised it isn't finished yet, but I have seen at least 3 groups (Eastern euro, .ru and .cn) that are investigating options to do this.
Goals appear varied: financial gain via extortion as well as selling access to compromised hosts to RaaS groups
So when you see the "You just got RCE and you use it to info dump" people, please kindly remind them that RCE isn't always as fancy as they would love to think