logo

Hadooken and K4Spreader: The 8220 Gang’s Latest Arsenal

ID: 914f1735-9dbb-5844-a4bb-6cef7eecbc69

STIX ID: report--914f1735-9dbb-5844-a4bb-6cef7eecbc69

Feed Name: Sekoia.io Blog

Threat Score
72/100

Date Published: 2024-09-30

Date Updated: 2026-04-29

Author: Jeremy Scion

...
...

**Executive Summary:** Sekoia TDR observed active exploitation of WebLogic RCE vulnerabilities to deploy K4Spreader/Hadooken, Tsunami, and PwnRig cryptomining malware across Linux and Windows hosts, linked by shared IOCs (domains, IPs, and a Monero wallet) to the 8220 Gang; approximately 200–250 infected hosts were observed, with persistence, lateral movement, AMSI bypass, and mining proxy infrastructure documented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.