Actors associated with the 8220 Gang have been observed exploiting a serious vulnerability in Oracle WebLogic Server to spread their malware.
See also: 2023: Over 26,000 security vulnerabilities discovered

The security vulnerability concerns CVE-2020-14883 (CVSS score: 7.2), a remote code execution flaw that can be used by hackers to take control of vulnerable servers.
“This vulnerability allows remote attackers to execute code using a gadget chain and is commonly chained with CVE-2020-14882 (an authentication bypass vulnerability that also affects Oracle Weblogic Server) or the use of stolen or weak credentials,” Imperva said in a report published last week.
The 8220 Gang has a history of exploiting known security flaws to distribute cryptojacking malware. Earlier this May, the group was spotted using another vulnerability in Oracle WebLogic servers (CVE-2017-3506, CVSS score: 7.4) to integrate devices into a crypto mining botnet.
See also: HCLTech: Ransomware incident hits the company
Recent attack chains documented by Imperva involve exploiting CVE-2020-14883 to craft specially crafted XML files and execute code responsible for deploying coin-stealing and mining malware such as Agent Tesla, rhajk, and nasqa.

"The group appears to be opportunistic when choosing its targets, with no clear trend in country or industry," said Imperva security researcher Daniel Johnston.
The campaign's targets include healthcare, telecommunications and financial services sectors in the US, South Africa, Spain, Colombia and Mexico.
See also: OpenAI: Presents “Readiness Framework” for managing risks in artificial intelligence
Johnston added: “The group relies on simple, publicly available exploits of known vulnerabilities and exploits easy targets to achieve its goals. Although it is considered uncontrollable, it is constantly evolving its techniques to evade detection.”
Information source: thehackernews.com
