8220 Gang Exploits Oracle WebLogic Server Flaws for Cryptocurrency Mining
ID: 922c4458-3631-5e3d-8c91-c60ab1cca70e
STIX ID: report--922c4458-3631-5e3d-8c91-c60ab1cca70e
Feed Name: The Hacker News
**Executive summary:** Security researchers (Trend Micro and QiAnXin XLab) report that the 8220 Gang (aka Water Sigbin) is exploiting known server vulnerabilities—including multiple Oracle WebLogic CVEs—to deliver a multi-stage, largely fileless malicious payload chain that loads a PureCrypter/Tixrgtluffu loader and an XMRig-based miner (masquerading as legitimate binaries) and uses a k4spreader installer to distribute the Tsunami DDoS botnet and PwnRig miner; the campaign employs reflective DLL injection, in-memory execution, scheduled tasks, Defender exclusions, and encrypted C2-config retrieval.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
