Skip to content
Threat Feed
medium advisory

Detection of Potential Reverse Shells via Java Applications on Linux

Adversaries are exploiting Linux-based Java applications to establish remote shells by spawning command-line interpreters following inbound network connections.

Java applications running on Linux systems are increasingly targeted as vectors for establishing reverse shells. Attackers exploit vulnerabilities within these applications to gain remote control by executing shell commands post-network communication. This technique involves an initial inbound connection to the Java process followed by the spawning of a child shell process (e.g., bash, sh, zsh) to facilitate C2 operations. Defenders should monitor for unexpected shell executions that originate from Java binaries, particularly when these processes have recently established external network connections. This activity is common in environments where Java is used to host web services or middleware, making distinction between legitimate administrative tasks and malicious activity critical.

Attack Chain

  1. Attacker identifies a vulnerable Java-based service (e.g., a web application or middleware) listening on the network.
  2. Attacker initiates an inbound connection (TCP/UDP) to the Java application's listening port.
  3. Attacker triggers a vulnerability within the Java application (e.g., deserialization, command injection).
  4. The compromised Java process (java binary) executes a shell command interpreter as a child process.
  5. The spawned shell (e.g., /bin/bash or /bin/sh) connects back to the attacker-controlled C2 infrastructure.
  6. The shell provides the attacker with interactive command execution capabilities on the host.
  7. Attacker performs further post-exploitation activities, including file exfiltration or lateral movement.

Impact

Successful exploitation allows for unauthorized remote access and persistent control over compromised Linux systems. This can lead to the exfiltration of sensitive data, deployment of further malicious payloads, or use of the host as a pivot point for lateral movement within the enterprise network.

Recommendation

Prioritize the identification of legitimate Java-based shell execution patterns in your environment to reduce noise.

  • Deploy the provided Sigma rule to monitor for suspicious child shell processes spawned by Java binaries post-network activity.
  • Establish a baseline of known legitimate Java processes that require shell access, such as specific deployment scripts or maintenance tools, and maintain an exclusion list for these specific paths or arguments.
  • Review network logs to identify connections from external IP addresses to Java-hosted services that subsequently trigger shell execution.
  • Isolate systems where unexpected shell activity is detected and investigate the parent Java process arguments to determine if a malicious JAR file is being executed.

Immediate actions

Deploy Sigma detection rule to monitor Java-spawned shells.

Detection Engineering 48h

Threat Hunt

Identify all Java applications executing shell commands.

T1059.004 medium high confidence hunt now

Data: Process creation logs showing Java as parent.

Detection coverage 1

Detect Potential Reverse Shell via Java

medium

Detects suspicious shell process creation spawned by Java binaries following an inbound network connection, a common indicator of reverse shell activity.

sigma tactics: command_and_control, execution techniques: T1059.004, T1071 sources: process_creation, linux

Detection queries are available on the platform. Get full rules →