Log4J Unifi (Ubiquiti) Attacks

Share This Post

As with many other applications, the Unifi application from Ubiquiti was vulnerable to the Log4J attacks. Morphisec has observed these attacks in the wild utilizing a Command-and-Control (C2) system that appears to be related to TA505 (aka Graceful Spider), and the C2 is correlated to some previous SolarWinds attacks.

These attacks are utilizing a Cobalt Strike beacon with a reverse TCP PowerShell script.

Morphisec Report: https://blog.morphisec.com/log4j-exploit-targets-vulnerable-unifi-network-applications

Indicators of Compromise

Indicator TypeIndicator
File Hash SHA256079089176ad528393c0641a630d90ca90a353a3c1765fb052e8c43ed45a29506
File Hash SHA2565e53ee9c3299a60b313bdfa3d8b8aaafae67d70eb565a7999e42139d51614462
CVECVE-2021-44228
File Hash SHA2562275247244f03091373f51d613939f5a96c48481c60832d443c112611142ceba
File Hash SHA256cccd16f0c8e1f490f9cf8b0a42d61b52185f0e44e66e098c4f116b3e19f75b1c
IPv4179.60.150.32
IPv4179.60.150.25
IPv4179.60.150.26
IPv4179.60.150.27
IPv4179.60.150.29
IPv4179.60.150.30


Reach out to our incident response team for help

More To Explore

Information Security News – 5/12/2025

Microsoft Sets Passkeys Default for New Accounts Article Link: https://thehackernews.com/2025/05/microsoft-sets-passkeys-default-for-new.html Accenture: What We Learned When Our CEO Got Deepfaked Article Link: https://www.computing.co.uk/event/2025/accenture-what-we-learned-when-our-ceo-got-deepfaked Ghost Students Creating

Information Security News – 5/5/2025

Cloudflare Sees a Big Jump in DDoS Attacks Article Link: https://www.bleepingcomputer.com/news/security/cloudflare-mitigates-record-number-of-ddos-attacks-in-2025/ Bring Your Own Computer Trend Gives Cyber Pros Chills, Yet It’s Here to Stay

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.