Attacks

Log4j: What You Need to Know

Table of Contents

On December 9, 2021, The Apache Foundation disclosed a critical security vulnerability in their Log4j utility that results in remote code execution. 

Log4j in Brief

Log4j is a utility for logging error messages which is very commonly used across much of the internet. The vulnerability (designated as CVE-2021-44228 by MITRE) stems from Log4j trusting user-generated content and then not only logging that content, but also interpreting specially crafted instructions found in that content. Threat actors are therefore able to execute arbitrary code in the vulnerable system.

News articles have said that threat actors are leveraging the log4j flaw to deploy ransomware, remote access Trojans, and web shells on vulnerable systems. Several botnets have already adapted to exploit the Log4j vulnerability.

How Common Is Log4j?

The affected version of Log4j is included in Apache Struts2, Solr, Druid, Flink, and Swift frameworks. Consequently, advisories and patches have been released by Amazon Web Services, IBM, and Oracle, among others. All told, millions of software applications could be affected.

How Lumu Addresses the Log4j Vulnerability

First, Lumu detects contacts with adversarial infrastructure that are potentially related to adversaries attempting to exploit this vulnerability. 

Second, Lumu systematically collects and analyzes network metadata. By doing so, Lumu gives organizations the ability to detect malicious activity related to malware families that are known to be using the Log4j vulnerability to communicate with their networks—and does so in real time.

Your Call to Action

Installing the most recent version of the Log4j utility is the paramount priority. At the time of writing, 2.16.0 is the latest version, but new versions are being released by The Apache Foundation.

Proofs of concept for the exploitation of Log4j are available in the public domain, which means that cybercriminals can access them as well. At this moment, it is critical to look for connections of adversaries trying to exploit the Log4j vulnerability, continuously monitor compromised assets, and automate response tasks associated with this threat. 

At Lumu, we believe that all companies can operate cybersecurity, no matter their size. That’s why we offer Lumu Free, which allows you to immediately see if your network is speaking with adversaries exploiting the Log4j vulnerability or others.

Recent Posts

  • Technical

From Fake CAPTCHA to Hidden Desktop: Unpacking CastleRAT and Operation Device Manager

Reading Time: 8 minsNew research from Lumu CTI dissects how TAG-150’s CastleRAT abuses ClickFix, Ethereum,…

5 days ago
  • Events

Fal.Con 2026: Stopping Infinity Offense With Lumu and CrowdStrike Falcon Next-Gen SIEM

Reading Time: 4 minsLumu CEO Ricardo Villadiego shares key takeaways from Fal.Con on unifying Lumu…

1 week ago
  • Events

3 Autonomous AI Risks Your Security Stack Isn’t Ready For

Reading Time: 6 minsDiscover three critical autonomous AI security risks breaking traditional enterprise stacks after…

3 weeks ago
  • Attacks

Advisory Alert: How The Gentlemen Ransomware Blinds Your EDR Defenses

Reading Time: 8 minsDiscover how threat actor The Gentlemen, aka Storm-2697, blinds endpoint security defenses…

1 month ago
  • Attacks

Advisory Alert: Defending Critical Infrastructure Against Industrial Control System Attacks

Reading Time: 5 minsA new FBI warning reveals cyberattacks on U.S. water systems have caused…

1 month ago
  • Product

Introducing the Lumu Threat Observatory™

Reading Time: 4 minsLearn how real-time threat tracking helps protect your organization from the latest…

1 month ago