Hackers using the name “z0Miner” are attacking Korean WebLogic to distribute malware, network tools, and scripts for further attacks.
See also: Malicious Google ads trick Mac users into installing Atomic Stealer malware

This group has a history of attacks against vulnerable servers such as Atlassian Confluence, Apache ActiveMQ, Log4j, and many others.
In 2020, researchers at Tencent first identified this threat actor . The “z0miner” malware group is known for exploiting CVE-2020-14882 and CVE-2020-14883 against Oracle WebLogic servers .
According to ASEC researchers, their most recent targets were Korean WebLogic servers, while several traces of tools such as FRP (Fast Reverse Proxy), NetCat , and AnyDesk.
According to reports shared with Cyber Security News, the z0miner malware group exploited these Korean WebLogic servers due to inadequate security setup and widespread exposure of server.
The malicious attacker could discover the Tomcat and server versions of these servers.
Once this information was collected, the threat actors used various tools, such as WebShell, FRP, and NetCat, to further exploit it.
Exploitation methods
WebShell
The z0miner malware group exploited the WebLogic vulnerability CVE-2020-14882 to upload a JSP webshell to the vulnerable system , enabling persistent presence and control over the system. Three webshells, namely JSP file Browser, Shack2 , and Behinder , were used. Furthermore, none of these webshells were detected by antivirus software products
See also: “TicTacToe Droppers” are used to distribute malware

Fast Reverse Proxy (FRP)
This tool was used for RDP (Remote Desktop Protocol) communication. In addition, both the default frpc version and a customized version were used. The default frpc loads a configuration file in *.INI and attempts the connection, while the customized frpc can be run without using a separate file.
NetCat
Netcat has the ability to read and write data over a network connection and has been detected in many webshells. The tools feature a remote shell feature, which allows them to bypass the firewall and take control of the target system.
Miner (XMRig)
The versions of XMRig used by the z0miner malware group are different for Windows and Linux . XMRig 6.18.0 was used on Windows, while 6.18.1 was used on Linux . To create persistence with the miner, the compromised user used the Task Scheduler (schtasks) or WMI event filter and configured it to read a PowerShell script from a specific address on Pastebin and execute it.
The z0miner malware group also used the address of the Monero Wallet and Mining Group.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, AnyDesk was one of the tools used by the threat actor as part of the webshell, but it was only used in cases where it exploits the Apache ActiveMQ vulnerability (CVE-2023-46604).
See also: The possible existence of Chinese malware in US systems is a "time bomb"

How can one protect themselves from malware?
Protecting yourself from malware like z0miner requires a number of preventative measures. First, it is important to keep your operating system and all installed programs up to date. Second, using reputable antimalware software is crucial. This software should be updated regularly so that it can deal with the latest threats. Third, security is essential. Finally, using strong passwords and changing them regularly can help protect you from z0miner malware. Also, using two-factor authentication can provide an extra layer of security.
Source: cybersecuritynews
