8220 Gang Exploiting Oracle WebLogic Server Vulnerability to Spread Malware
ID: 1f669d2a-4337-5a26-ab8f-4da02103f57e
STIX ID: report--1f669d2a-4337-5a26-ab8f-4da02103f57e
Feed Name: The Hacker News
The Imperva-backed report describes the 8220 Gang exploiting Oracle WebLogic vulnerabilities (notably CVE-2020-14883, often chained with CVE-2020-14882 or using weak/stolen credentials) to execute remote code and deploy cryptomining and information-stealing malware such as Agent Tesla, rhajk, and nasqa against organizations in healthcare, telecommunications, and financial services across several countries; the group is opportunistic and uses publicly available exploits and evolving tactics to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
