Security researchers have revealed details about the activity of the “8220 Gang,” which exploits vulnerabilities in Oracle WebLogic Server for the purpose of cryptocurrency mining.

According to Trend Micro researchers Ahmed Mohamed Ibrahim, Shubham Singh, and Sunil Bharti, "the threat actor uses fileless techniques, such as DLL injection. These techniques allow the malware to execute exclusively in memory, thus avoiding disk-based detection mechanisms."
Read more: New Unfurling Hemlock floods systems with malware
The cybersecurity firm is tracking a financially motivated malicious actor named Water Sigbin, who exploits vulnerabilities in Oracle WebLogic Server such as CVE-2017-3506, CVE-2017-10271, and CVE-2023-21839 to access the miner payload via the multi-stage loading technique.
A successful infiltration is followed by the deployment of a PowerShell script, which is responsible for placing a loader (“wireguard2-3.exe”) that mimics the legitimate WireGuard VPN. However, in reality, it launches another binary (“cvtres.exe”) into memory via a DLL (“Zxpus.dll”).
The injected executable acts as a conduit for loading the PureCrypter loader (“Tixrgtluffu.dll”). This, in turn, exports hardware to a remote server and creates scheduled tasks to run the miner. In addition, it ensures that malicious files are excluded from Microsoft Defender Antivirus.
See more: Mac users exposed to info-stealer malware via Google Ads
The command and control (C2) server sends an encrypted message containing the XMRig configuration settings. The loader then retrieves and executes the miner from a domain controlled by the hacker, disguised as “AddinProcess.exe,” a legitimate Microsoft binary.
Furthermore, following the presentation of a new installation tool by the QiAnXin XLab team, called k4spreader, it has been used by the 8220 Gang since at least February 2024 to deliver the botnet and the PwnRig mining program.

The malware, which is currently under development and is in a shell version, exploits security flaws such as Apache Hadoop YARN, JBoss, and Oracle WebLogic Server to infiltrate sensitive targets.
Read also: Why is Temu considered “dangerous malware”?
“K4spreader is written in CGO and offers features such as system persistence, downloading and updating, and distributing other malware to execute,” the company said. It also noted that it is designed to disable firewalls ,neutralize competing botnets (e.g., kinsing), and report on operational status.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
