logo

Hackers Using k4spreader Tool To Install DDoS Botnet And Miners

ID: a65da6b3-98af-5676-b06d-b40b3596542c

STIX ID: report--a65da6b3-98af-5676-b06d-b40b3596542c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2024-06-26

Date Updated: 2026-04-21

Author: Aman Mishra

...
...

A new ELF dropper named k4spreader, attributed to the "8220" (Water Sigbin) mining group, was observed in June 2024; it uses a modified UPX packer to evade detection, exploits multiple remote code execution vulnerabilities to spread, establishes persistence via bash/init/systemd service modifications, and drops Tsunami DDoS and PwnRig Monero mining payloads while contacting identified C2 domains and an IP address.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.