logo

z0Miner targeting WebLogic servers (Campaign)

ID: 5518db3b-6880-5d5a-b5ed-efa66e14861a

STIX ID: report--5518db3b-6880-5d5a-b5ed-efa66e14861a

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-03-06

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed the z0Miner group actively exploiting WebLogic and an ActiveMQ flaw to upload JSP web shells and use compromised Korean WebLogic servers as download hosts for malware. The actors deliver payloads via certutil/powershell on Windows and curl on Linux, deploy XMRig miners, remote tools (Netcat, AnyDesk), establish persistence (WMI Event Filters/Task Scheduler), and use FRP for RDP; affected files should be removed and workloads redeployed from clean states.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.