logo

8220 Gang Deploys a New Campaign with Upgraded Techniques

ID: b1facca4-7841-5c3f-9901-f1a122496d08

STIX ID: report--b1facca4-7841-5c3f-9901-f1a122496d08

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2022-07-07

Date Updated: 2026-04-26

...
...

This report analyzes an active campaign by the 8220 gang that exploited a Confluence RCE (CVE-2022-26134) and misconfigured Docker to run a malicious 'jira?confluence' shell script, which installs UPX-packed cryptominers (dbuser), an IRC backdoor (Tsunami/bashirc), scanners (masscan, spirit), and SSH brute-force tools to propagate. The attackers implement persistence via cron and backup loops, disable cloud security agents and SELinux, delete logs, tune kernel parameters for mining, and use multiple C2 channels; the report includes detailed IOCs (file hashes, IPs, domain) and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.