Hadooken and K4Spreader: The 8220 Gang’s Latest Arsenal
ID: 914f1735-9dbb-5844-a4bb-6cef7eecbc69
STIX ID: report--914f1735-9dbb-5844-a4bb-6cef7eecbc69
Feed Name: Sekoia.io Blog
Threat Score
**Executive Summary:** Sekoia TDR observed active exploitation of WebLogic RCE vulnerabilities to deploy K4Spreader/Hadooken, Tsunami, and PwnRig cryptomining malware across Linux and Windows hosts, linked by shared IOCs (domains, IPs, and a Monero wallet) to the 8220 Gang; approximately 200–250 infected hosts were observed, with persistence, lateral movement, AMSI bypass, and mining proxy infrastructure documented.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
