Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » 8220 Gang Exploits Oracle WebLogic Server Flaws to Mine Cryptocurrencies
Global Security

8220 Gang Exploits Oracle WebLogic Server Flaws to Mine Cryptocurrencies

AdminBy AdminJuly 7, 2024No Comments2 Mins Read
Cryptocurrency Mining
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


June 28, 2024Information hallMalware / cryptocurrency

Cryptocurrency mining

Security researchers have shed more light on the cryptocurrency mining operation he ran 8220 gang exploiting known security flaws in Oracle WebLogic Server.

“The threat actor uses fileless execution techniques using DLL mapping and process injection, allowing the malware code to run exclusively in memory and avoid disk-based detection mechanisms,” Trend Micro researchers Ahmed Mohammed Ibrahim, Shubham Singh and Sunil Bharti said in a new analysis published today.

A cyber security firm is tracking a financially motivated actor known as Water Sigbin use a weapon of vulnerability in Oracle WebLogic Server, for example CVE-2017-3506, CVE- 2017-10271and CVE-2023-21839 to initially access and drop the Miner payload using a multi-stage download technique.

A successful anchoring follows deploying a PowerShell script which is responsible for removing a first-stage bootloader (“wireguard2-3.exe”) that mimics the legitimate WireGuard VPN application but actually runs another binary (“cvtres.exe”) in memory using a DLL (” Zxpus.dll” ).

Cyber ​​security

The entered executable file serves as the download channel PureCrypter Downloader (“Tixrgtluffu.dll”), which in turn releases hardware information to a remote server and creates scheduled tasks to run the miner, and excludes malicious files from Microsoft Defender Antivirus.

In response, the command-and-control (C2) server responds with an encrypted message containing XMRig configuration details, after which the bootloader extracts and runs the miner from the attacker-controlled domain, issuing it as “AddinProcess.exe,” a legitimate Microsoft binary.

Cryptocurrency mining

The development comes as the QiAnXin XLab team detailed a new installation tool used by the 8220 Gang called k4spreader since at least February 2024 to provide Tsunami DDoS botnet and PwnRig mining program.

The malware, which is currently in development and has a shell version, exploits security flaws such as Apache Hadoop YARN, JBossand Oracle WebLogic Server to penetrate sensitive targets.

“k4spreader is written in CGO, including saving the system, loading and updating itself, and releasing other malware to execute,” the company saidadding that it is also designed to disable the firewall, stop competing botnets (such as kinsing), and print operational status.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025

Mirror aims Japan and Taiwan with Roysingmouse and upgraded malicious program

May 8, 2025

Only security tools do not protect you – control efficiency makes

May 8, 2025

Russian hackers using Flackfix Fake CAPTCHA to deploy new malware LostKeys

May 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025

Mirror aims Japan and Taiwan with Roysingmouse and upgraded malicious program

May 8, 2025

Only security tools do not protect you – control efficiency makes

May 8, 2025

Russian hackers using Flackfix Fake CAPTCHA to deploy new malware LostKeys

May 8, 2025

Cisco Patches Cve-2025-20188 (10.0 CVSS) in iOS XE, which allows root feat via JWT

May 8, 2025

Ottokit WordPress plugin with 100K+ Instals Hit Gratoits, focused on several disadvantages

May 7, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.