EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/log4shell-2021
171/430

File EL-0260CriticalResolvedCyberattack / Supply Chain Attack

Log4Shell — Apache Log4j Remote Code Execution Vulnerability

Also filed as CVE-2021-44228 · Log4j RCE · JNDI Injection Vulnerability

Log4Shell was a critical vulnerability found in the Apache Log4j logging library, allowing for Remote Code Execution (RCE). The flaw exploited the Java Naming and Directory Interface (JNDI) functionality, enabling attackers to execute arbitrary code by injecting specially crafted strings into log messages. Due to the library's ubiquity across countless enterprise applications, the vulnerability posed an immediate, global threat.

  • #log4j
  • #rce
  • #jndi
  • #cve-2021-44228
  • #apache
  • #supply-chain
Notoriety10/10
Event
9 Dec 2021
Disclosed
9 Dec 2021
Target
Global Technology Infrastructure
Actor
Nation-State Actors / Criminal Gangs
Scale
N/A (Exploitation focused)
Status
Resolved

01Summary

The vulnerability, formally designated CVE-2021-44228, resided in the Log4j library's handling of message lookups. When an application logged a user-controlled string, the library could interpret specific patterns (like `${jndi:ldap://...}`) as commands. An attacker could submit this string via various input vectors (e.g., HTTP headers, login forms), causing the vulnerable application to connect to an attacker-controlled LDAP server. This server would then return a malicious object reference, which the vulnerable Java runtime would deserialize and execute, leading to full system compromise. The rapid disclosure and subsequent exploitation by various threat actors highlighted the extreme risk posed by deeply embedded, foundational software components.

02Background

Logging libraries are essential components of modern software, recording operational data for debugging and auditing. Apache Log4j is one of the most widely adopted logging frameworks in the Java ecosystem. The vulnerability was not a flaw in the core logging mechanism itself, but rather in how it processed and interpreted specific, complex lookup patterns within the logged data.

03Key revelations

  1. 01The vulnerability demonstrated the extreme risk inherent in widely used, foundational open-source libraries.
  2. 02The speed and scale of exploitation showed the effectiveness of automated, low-effort, high-impact attacks.
  3. 03The incident forced a global, immediate overhaul of software supply chain security practices.

04Technical analysis

The vulnerability exploited the JNDI lookup feature, which allows Java applications to retrieve resources from various naming services (like LDAP or RMI). By crafting a payload that directed the JNDI lookup to an attacker-controlled server (e.g., via LDAP), the attacker could force the victim machine to download and execute arbitrary code, bypassing typical input validation mechanisms.

Attack vector
Injection (via user-controlled input fields, HTTP headers, or network traffic that gets logged)
Attack method
Remote Code Execution (RCE) via JNDI Injection
Initial access
Network-based exploitation (via logging input)
Lateral movement
Remote execution of payloads
Persistence
Installation of backdoors or web shells
Exfiltration
Network communication (e.g., DNS tunneling, direct data transfer)
Tool / malware
JNDI Payload
Malware type
Exploit

Vulnerabilities exploited

  • CVE-2021-44228

MITRE ATT&CK techniques

  • T1190
  • T1566.001

05Threat actor

The exploitation of Log4Shell was not attributed to a single group, but rather served as a massive, low-effort testing ground for various threat actors. This demonstrated that even sophisticated nation-state groups could leverage simple, foundational flaws for maximum geopolitical impact.

Aliases

  • APT Groups
  • Script Kiddies
  • Cybercriminals

MITRE groups

  • T1566.001
  • T1190

Attribution sources

  • Mandiant
  • CISA
  • Microsoft
  • Google

06Victims and impact

Additional victims

  • Cloud Service Providers
  • Enterprise Networks
  • IoT Devices

Countries affected

  • Global

07Data exposed

Data types

  • System logs
  • Credentials
  • Source Code

Notable documents

  • CVE-2021-44228 Advisory
  • Apache Log4j Security Update

08Financial damage

Estimated costs include remediation, downtime, and potential data breach penalties.

09Timeline

  1. 2021-12-09Vulnerability disclosed and initial exploitation begins.
  2. 2021-12-10Initial patches and mitigation guidance released by Apache and security vendors.
  3. 2021-12-15Major security firms confirm widespread exploitation across critical infrastructure.

10Key figures

  • Chen ZhaojunDiscoverer/Researcher · Alibaba CloudChineseCredited with initial discovery/disclosure.

11On the record

The vulnerability was a textbook example of a supply chain risk.

CISA, Describing the systemic risk posed by the library.

12Reaction and fallout

Public reaction

The public reaction was one of alarm, leading to a massive, coordinated effort across the tech industry to patch and audit systems. It highlighted the fragility of modern, interconnected digital infrastructure.

Political impact

The incident spurred immediate governmental and industry calls for mandatory software bill of materials (SBOM) generation and stricter supply chain risk management policies.

Geopolitical consequences

The vulnerability was rapidly exploited by multiple nation-state and criminal groups, demonstrating the ease with which geopolitical adversaries could conduct large-scale, low-effort espionage operations.

13Legal

No specific major legal outcome was immediately visible, but the incident accelerated regulatory focus on cybersecurity due diligence and supply chain accountability.

Civil lawsuits

  • Class-action lawsuits against affected software vendors (ongoing/potential)

14Aftermath

Policy changes

  • Mandatory Software Bill of Materials (SBOM) adoption
  • Increased scrutiny of open-source dependencies

Regulatory changes

  • Enhanced requirements for critical infrastructure resilience (e.g., NIST frameworks)
  • Increased focus on supply chain risk in government procurement

Security improvements

  • Implementation of runtime application self-protection (RASP)
  • Network segmentation to limit blast radius
  • Mandatory dependency scanning (SCA tools)

15Significance and legacy

Significance

Log4Shell is historically significant because it was one of the first widely exploited, high-impact vulnerabilities to demonstrate the systemic risk of open-source software dependencies. It forced the global cybersecurity community to treat the software supply chain as a primary attack surface, leading to immediate policy and technical shifts.

Legacy

The incident permanently changed how organizations manage software risk, making SBOMs a critical industry standard. It also accelerated the adoption of zero-trust architectures, as reliance on single, trusted components proved dangerously insufficient.

16Disclosure and media

Authentication
Code review and public proof-of-concept exploitation

Media partners

  • The New York Times
  • BBC News
  • Reuters

Publishing organisations

  • CISA
  • Mandiant
  • Microsoft

17Related files

Related events

  • Shellshock

Went on to inspire

  • Supply Chain Attacks (General)

18Field notes

  1. 01The vulnerability was so critical that it was assigned a CVSS score of 10.0, indicating maximum severity.
  2. 02The speed of exploitation was unprecedented, with automated tools targeting the flaw within hours of disclosure.

19Resolution

The Apache Software Foundation released patched versions of Log4j, and organizations globally implemented immediate patching, configuration changes, and network monitoring to detect exploitation attempts.

20Sources

Official documents

  • Apache Log4j Security Advisory
  • CISA Alert AA21-111A

References

  1. [1]CISA
  2. [2]Mandiant
  3. [3]Apache Software Foundation
Fact sheetEL-0260

Dates

Event
9 Dec 2021
Started
9 Dec 2021
Ended
1 Mar 2022
Duration
1 days
Discovered
9 Dec 2021
Disclosed
9 Dec 2021
Resolved
10 Dec 2021
Ongoing
No

Target

Organisation
Apache Log4j Library Users
Type
Technology Company
Sector
Software/IT Services
Country
Global
Gov. level
Federal

Actor

Name
Nation-State Actors / Criminal Gangs
Type
Nation-State Actor
Motivation
Espionage, data theft, system disruption, and financial gain.
Attribution
Contested
Status
Active
Arrested
No
Convicted
No

Data

Volume
N/A (Exploitation focused)
Sensitivity
Mixed
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Bitcoin/Monero

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.