• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
8220 gang exploits oracle weblogic server flaws for cryptocurrency mining

8220 Gang Exploits Oracle WebLogic Server Flaws for Cryptocurrency Mining

You are here: Home / General Cyber Security News / 8220 Gang Exploits Oracle WebLogic Server Flaws for Cryptocurrency Mining
June 28, 2024

Security researchers have lose a lot more light on the cryptocurrency mining operation executed by the 8220 Gang by exploiting acknowledged security flaws in the Oracle WebLogic Server.

“The risk actor employs fileless execution approaches, working with DLL reflective and process injection, making it possible for the malware code to operate solely in memory and stay clear of disk-dependent detection mechanisms,” Development Micro scientists Ahmed Mohamed Ibrahim, Shubham Singh, and Sunil Bharti explained in a new evaluation posted currently.

The cybersecurity business is tracking the fiscally determined actor beneath the title Drinking water Sigbin, which is regarded to weaponize vulnerabilities in Oracle WebLogic Server this sort of as CVE-2017-3506, CVE- 2017-10271, and CVE-2023-21839 for preliminary entry and drop the miner payload by way of multi-stage loading procedure.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


A productive foothold is followed by the deployment of PowerShell script which is accountable for dropping a first-stage loader (“wireguard2-3.exe”) that mimics the respectable WireGuard VPN application, but, in fact, launches another binary (“cvtres.exe”) in memory by usually means of a DLL (“Zxpus.dll”).

Cybersecurity

The injected executable serves as a conduit to load the PureCrypter loader (“Tixrgtluffu.dll”) that, in transform, exfiltrates components details to a remote server and results in scheduled tasks to run the miner as perfectly as excludes the destructive information from Microsoft Defender Antivirus.

In response, the command-and-manage (C2) server responds with an encrypted information made up of the XMRig configuration specifics, pursuing which the loader retrieves and executes the miner from an attacker-controlled area by masquerading it as “AddinProcess.exe,” a authentic Microsoft binary.

Cryptocurrency Mining

The growth comes as the QiAnXin XLab group in depth a new installer tool utilised by the 8220 Gang identified as k4spreader due to the fact at least February 2024 to produce the Tsunami DDoS botnet and the PwnRig mining software.

The malware, which is at the moment under progress and has a shell edition, has been leveraging security flaws these kinds of as Apache Hadoop YARN, JBoss, and Oracle WebLogic Server to infiltrate susceptible targets.

“k4spreader is written in cgo, including method persistence, downloading and updating itself, and releasing other malware for execution,” the business claimed, introducing it’s also built to disable the firewall, terminate rival botnets (e.g., kinsing), and printing operational standing.

Identified this write-up interesting? Comply with us on Twitter  and LinkedIn to study much more exceptional content we publish.


Some pieces of this posting are sourced from:
thehackernews.com

Previous Post: «combatting the evolving saas kill chain: how to stay ahead Combatting the Evolving SaaS Kill Chain: How to Stay Ahead of Threat Actors
Next Post: GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 Others gitlab releases patch for critical ci/cd pipeline vulnerability and 13»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.