8220 Gang Deploys a New Campaign with Upgraded Techniques
ID: b1facca4-7841-5c3f-9901-f1a122496d08
STIX ID: report--b1facca4-7841-5c3f-9901-f1a122496d08
Feed Name: Aqua Security Blog
This report analyzes an active campaign by the 8220 gang that exploited a Confluence RCE (CVE-2022-26134) and misconfigured Docker to run a malicious 'jira?confluence' shell script, which installs UPX-packed cryptominers (dbuser), an IRC backdoor (Tsunami/bashirc), scanners (masscan, spirit), and SSH brute-force tools to propagate. The attackers implement persistence via cron and backup loops, disable cloud security agents and SELinux, delete logs, tune kernel parameters for mining, and use multiple C2 channels; the report includes detailed IOCs (file hashes, IPs, domain) and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
