Attackers began exploiting the Spring Framework remote code execution flaw Spring4Shell (CVE-2022-22965) to plant JSP web shells on vulnerable Apache Tomcat servers and deliver cryptocurrency miners. Trend Micro reported attempts that wrote a web shell named zbc0fb.jsp into the Tomcat web root, then used it to run operating-system-specific payloads on both Windows and Linux systems. The activity followed Spring's disclosure of the RCE issue and its guidance to upgrade to fixed releases, including Spring Framework 5.3.18 and 5.2.20 or later.
On Windows targets, the observed chain used hidden PowerShell execution to fetch ldr.ps1 in memory, which then downloaded a miner from 194.145.227.21. The miner was designed to disable the firewall, kill competing miner processes and services bound to common mining ports, launch the payload, and establish persistence through a scheduled task named BrowserUpdate and a Windows Run key. The intrusion pattern mirrors earlier enterprise-server exploitation seen in incidents such as WebLogic RCE leading to XMRig, underscoring how rapidly newly disclosed Java server flaws are weaponized for opportunistic cryptomining.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Spring released fixes for Spring4Shell in Spring Framework versions 5.3.18 and 5.2.20, and recommended Spring Boot versions 2.6.6 or 2.5.12 alongside the patched framework releases. The issue was tracked as CVE-2022-22965.
Spring published an early announcement about a remote code execution issue in Spring Framework, later tracked as CVE-2022-22965.
VMware publicly disclosed the Spring Framework remote-code-execution vulnerability CVE-2022-22965, commonly known as Spring4Shell. The disclosed exploitation path involved data-binding abuse under specific Spring, JDK, Tomcat, and WAR deployment conditions.
Trend Micro reported exploitation attempts for Spring4Shell in which attackers used a crafted HTTP GET request to write a JSP web shell named zbc0fb.jsp into Tomcat's web root and then deliver cryptocurrency-mining payloads for Windows and Linux systems. The report said it could not confirm whether the exploitation attempts were successful.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcetrendmicro.com
Open sourcespring.io
Open sourceisc.sans.edu
Open sourcetanzu.vmware.com
Open sourcethedfirreport.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.