← Latest papers
💻 computer science

A Longitudinal Measurement Study of Log4Shell Exploitation from a Reactive Network Telescope

This paper presents a longitudinal measurement study of Log4Shell exploitation from an Indian network telescope between December 2021 and October 2025, revealing that the vulnerability remains active years after disclosure with evolving tactics including infrastructure consolidation and increased obfuscation, thereby highlighting the critical need for long-term, geographically diverse monitoring to fully understand the lifecycle of critical software vulnerabilities.

Original authors: Aakash Singh, Kuldeep Singh Yadav, V. Anil Kumar, Samiran Ghosh, Pranita Baro, Basavala Bhanu Prasanth

Published 2026-05-19
📖 5 min read🧠 Deep dive

Original authors: Aakash Singh, Kuldeep Singh Yadav, V. Anil Kumar, Samiran Ghosh, Pranita Baro, Basavala Bhanu Prasanth

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the internet as a massive, bustling city. In this city, almost every building (software application) uses the same standard set of blueprints for its security guards and logging systems. One of these blueprints, called Log4j, had a hidden flaw in its design. This flaw, known as Log4Shell, was like a secret backdoor that allowed anyone who knew the code to walk right in, bypass the locks, and take control of the building.

This paper is a four-year surveillance report on how criminals tried to use this backdoor. Instead of just watching the first few days of chaos (which other studies did), the researchers set up a special "trap" in India and watched what happened from December 2021 all the way to October 2025.

Here is the story of what they found, told in simple terms:

1. The Setup: The "Ghost" Trap

The researchers didn't build a fake building to trick hackers. Instead, they built a Network Telescope. Think of this as a dark, empty street in the middle of the city where no one lives.

  • How it works: When a hacker scans the city looking for open doors, they eventually knock on a door on this empty street.
  • The Trick: Usually, an empty street stays silent. But this telescope is "reactive." When someone knocks, it politely says, "Hello, I'm here!" and keeps the conversation going just long enough to see what the hacker wants to do next. This allowed the researchers to catch the hackers' actual instructions (the "payload") without actually running any real software that could be hacked.

2. The Timeline: From a Stampede to a Sniper

The study reveals that the Log4Shell threat didn't just disappear after the news broke. It evolved in three distinct phases:

  • Phase 1: The Panic (Late 2021):
    When the flaw was first revealed, it was like a stampede. Hackers from all over the world (especially the US, Germany, and Argentina) started running wild, knocking on every single door in the city, hoping to find an open one. It was chaotic, loud, and everywhere.

  • Phase 2: The Shift (2022–2023):
    As people started fixing their locks (patching the software), the stampede slowed down. The hackers didn't give up, though. They changed tactics. Instead of running wild, they started using specialized teams.

    • The Analogy: Imagine the crowd of thousands shrinking down to just a few very organized groups. By 2023, almost all the attacks were coming from just one country (Poland) and a tiny number of specific IP addresses. It went from a "spray and pray" approach to a "surgical strike" approach.
  • Phase 3: The Persistence (2024–2025):
    Even years later, the attacks didn't stop. In fact, they became even more concentrated. By 2025, nearly all the scanning was coming from Germany, driven by a single network. The hackers had settled into a long-term routine, using the same few "bases" to keep testing for victims.

3. The "Bases": Where the Hackers Hide

The researchers also tracked where the hackers sent their instructions.

  • Early Days: In the beginning, hackers used many different "command centers" (servers) scattered around the world (US, Europe, Asia).
  • Later Days: Over time, these command centers consolidated. The hackers stopped using hundreds of different servers and started relying on just a handful of very stable, long-lasting ones. It's like a criminal gang that used to rent a new apartment every week but eventually bought a single, permanent headquarters.

4. The "Secret Handshakes": Hiding in Plain Sight

At first, the hackers sent clear messages like "Open the door." But as security experts got better at spotting these messages, the hackers started using obfuscation (hiding tricks).

  • The Analogy: Instead of writing "JNDI" (the code for the backdoor), they started writing things like "J-N-D-I" or using strange symbols to break up the word. It's like a spy changing their accent or wearing a disguise so the security guard doesn't recognize them. The researchers had to build a special decoder to peel back these layers and see what the hackers were really saying.

5. The Big Takeaway

The most important lesson from this four-year watch is that critical software flaws don't just go away.

  • Even though the "bug" was fixed years ago, the attackers kept coming back.
  • They didn't stop because the news cycle moved on; they just got smarter, more organized, and more persistent.
  • The study shows that to truly understand a security threat, you can't just look at the first few weeks. You have to watch it for years, and you have to look at it from different parts of the world (like India), because the attack patterns can look very different depending on where you are standing.

In summary: Log4Shell was a massive crack in the foundation of the internet. While the initial panic was loud and chaotic, the real story is a quiet, persistent, and evolving campaign by hackers who refused to let go, adapting their methods over four years to keep trying to break in.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →