logo

8220 Gang Exploiting WebLogic Vulnerabilities for Cryptojacking (Campaign)

ID: b59a581f-7c17-5561-b779-d3c03356c13c

STIX ID: report--b59a581f-7c17-5561-b779-d3c03356c13c

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2024-06-30

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The report details a cryptojacking campaign by the 8220 Gang (Water Sigbin) exploiting WebLogic CVE-2017-3506 to deploy a multi-stage payload masquerading as WireGuard; the chain uses a PowerShell dropper, a first-stage loader (wireguard2-3.exe), Zxpus.dll, a PureCrypter loader, and ultimately the XMRig miner, employing in-memory reflective DLL/process injection, scheduled-task persistence, and Windows Defender exclusion modifications to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.