8220 Gang Exploiting WebLogic Vulnerabilities for Cryptojacking (Campaign)
ID: b59a581f-7c17-5561-b779-d3c03356c13c
STIX ID: report--b59a581f-7c17-5561-b779-d3c03356c13c
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-06-30
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
The report details a cryptojacking campaign by the 8220 Gang (Water Sigbin) exploiting WebLogic CVE-2017-3506 to deploy a multi-stage payload masquerading as WireGuard; the chain uses a PowerShell dropper, a first-stage loader (wireguard2-3.exe), Zxpus.dll, a PureCrypter loader, and ultimately the XMRig miner, employing in-memory reflective DLL/process injection, scheduled-task persistence, and Windows Defender exclusion modifications to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
