z0Miner targeting WebLogic servers (Campaign)
ID: 5518db3b-6880-5d5a-b5ed-efa66e14861a
STIX ID: report--5518db3b-6880-5d5a-b5ed-efa66e14861a
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-03-06
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers observed the z0Miner group actively exploiting WebLogic and an ActiveMQ flaw to upload JSP web shells and use compromised Korean WebLogic servers as download hosts for malware. The actors deliver payloads via certutil/powershell on Windows and curl on Linux, deploy XMRig miners, remote tools (Netcat, AnyDesk), establish persistence (WMI Event Filters/Task Scheduler), and use FRP for RDP; affected files should be removed and workloads redeployed from clean states.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
