19 December 2023

China-linked 8220 gang exploits Oracle WebLogic bugs to deploy malware


China-linked 8220 gang exploits Oracle WebLogic bugs to deploy malware

A threat actor known as the 8220 gang, believed to be of Chinese origin, has been spotted exploiting a high-severity vulnerability in the Oracle WebLogic platform to deploy AgentTesla, rhajk and nasqa malware variants.

The said flaw is CVE-2020-14883, an improper input validation issue within the Console component in Oracle WebLogic Server, which could be exploited for remote code execution.

“This vulnerability allows remote authenticated attackers to execute code using a gadget chain and is commonly chained with CVE-2020-14882 (an authentication bypass vulnerability also affecting Oracle Weblogic Server) or the use of leaked, stolen, or weak credentials,” Imperva’s threat research team explained in a report. “The 8220 gang uses two different gadget chains: one enables the loading of an XML file, which then contains a call to the other and enables execution of commands on the OS.”

First observed in 2017, the 8220 gang has been known to target Drupal, Hadoop YARN, and Apache Struts2 applications to propagate cryptojacking malware. Most recently, Trend Micro reported the group’s use of the CVE-2017-3506 WebLogic flaw to infect targeted systems.

The group has been seen exploiting the following vulnerabilities in its attacks:

The group appears to be opportunistic when selecting their targets, with no clear trend in country or industry. It was observed targeting healthcare, telecommunications, and financial services in the US, South Africa, Spain, Columbia, and Mexico. The 8220 gang appears to use custom tools written in Python to launch their attack campaigns, and the attacking IPs (located in the US, Mexico and Russia) are associated with known hosting companies, Imperva said.

Back to the list

Latest Posts

 Phemex crypto exchange hit by $85 million theft

Phemex crypto exchange hit by $85 million theft

Due to the breach the platform suspended deposits and withdrawals temporarily.
28 January 2025
Ransomware actors targeting ESXi hypervisors with SSH Tunneling for persistence

Ransomware actors targeting ESXi hypervisors with SSH Tunneling for persistence

Threat actors are leveraging known bugs in ESXi appliances or exploiting compromised administrator credentials to gain initial access.
28 January 2025
EU sanctions three Russian intelligence officers for cyberattacks on Estonia

EU sanctions three Russian intelligence officers for cyberattacks on Estonia

In 2020, the trio played key roles in a sophisticated cyberattack that targeted various Estonian government ministries.
28 January 2025