The ongoing exploit activities of the Log4Shell vulnerability (CVE-2021-44228) in the popular Apache Log4j open source logging tool remain on a high level one year after it was first disclosed on December 9, 2021, Arctic Wolf noted in recent research.

The research showed one-quarter of the security vendor’s customers have been targeted with Log4Shell exploitation attempts since January, and Arctic Wolf found threat actors continue to use the exploit throughout the year.

“When we originally investigated this vulnerability in December 2021, we immediately knew this one would have a long-lasting impact on organizations around the world and that it would be attractive for Cyber Criminals to exploit. This is exactly what we have seen over the past year,” Adrian Korn, Manager of threat intelligence research for Arctic Wolf Labs, wrote in response to questions.

“Cyber Criminals have not slowed down too much in their use of Log4Shell exploits in attacks. They continue to find unpatched servers exposed to the Internet and exploit those to gain initial access. We have seen this happen in several Ransomware cases our Incident Response team has investigated,” Korn added.

In Arctic Wolf’s earlier report, Log4Shell ranked second among the top external exploits used by threat actors to deploy ransomware in 2022, behind only ProxyShell (CVE-2021-34473), which is a vulnerability in Microsoft Exchange announced in 2021.

Log4Shell represents 11% of incident response cases investigated by Arctic Wolf. And about 60% of those cases were attributed to three ransomware groups: LockBit (26.9%), Conti (19.2%), and Alphv/BlackCat (11.5%).

Those exploits had an impact on organizations financially, as the average Log4Shell incident response engagement cost over $90,000, Arctic Wolf reported.

Identifying Log4Shell Is Not an Easy Task

On high alert for Log4Shell exploitation since last December, Korn pointed out that many organizations still face challenges identifying systems as vulnerable due to the embedded nature of the Log4J library in thousands of applications.

“For this reason, Log4Shell will continue to have a long tail,” he said. “Unless organizations are doing host-based vulnerability scanning, it can be challenging for them to identify systems with Log4j under the hood.”

Korn said that’s why Arctic Wolf Labs released the Log4Shell Deep Scan open-source tool after the discovery to help smaller under-resourced organizations address this issue. The tool can scan a host’s file system to identify Java applications and libraries with vulnerable Log4j code, the vendor claims.