logo

8220 Gang Exploiting Oracle WebLogic Server Vulnerability to Spread Malware

ID: 1f669d2a-4337-5a26-ab8f-4da02103f57e

STIX ID: report--1f669d2a-4337-5a26-ab8f-4da02103f57e

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2023-12-19

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

The Imperva-backed report describes the 8220 Gang exploiting Oracle WebLogic vulnerabilities (notably CVE-2020-14883, often chained with CVE-2020-14882 or using weak/stolen credentials) to execute remote code and deploy cryptomining and information-stealing malware such as Agent Tesla, rhajk, and nasqa against organizations in healthcare, telecommunications, and financial services across several countries; the group is opportunistic and uses publicly available exploits and evolving tactics to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.