logo

8220 Gang Exploits Oracle WebLogic Server Flaws for Cryptocurrency Mining

ID: 922c4458-3631-5e3d-8c91-c60ab1cca70e

STIX ID: report--922c4458-3631-5e3d-8c91-c60ab1cca70e

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-28

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Security researchers (Trend Micro and QiAnXin XLab) report that the 8220 Gang (aka Water Sigbin) is exploiting known server vulnerabilities—including multiple Oracle WebLogic CVEs—to deliver a multi-stage, largely fileless malicious payload chain that loads a PureCrypter/Tixrgtluffu loader and an XMRig-based miner (masquerading as legitimate binaries) and uses a k4spreader installer to distribute the Tsunami DDoS botnet and PwnRig miner; the campaign employs reflective DLL injection, in-memory execution, scheduled tasks, Defender exclusions, and encrypted C2-config retrieval.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.