luoxk is a malicious activity cluster associated with opportunistic exploitation of internet-facing services, cryptocurrency mining, and distributed denial-of-service operations. The group was observed exploiting CVE-2018-2893 in Oracle WebLogic Server shortly after a patch became available, indicating rapid weaponization of newly disclosed vulnerabilities for initial access. Activity linked to luoxk dates to at least 2017. The cluster has used multi-stage payload delivery across both Windows and Linux systems. Observed tooling included a Java-based payload that performed operating-system checks and then executed platform-specific download-and-execute logic. On Windows, the malware attempted to terminate security software processes before launching follow-on payloads. On Linux and Unix-like systems, shell scripts were used to retrieve and execute additional components, including cryptocurrency miners and DDoS malware. The campaign also showed worm-like exploitation behavior against RMI services. luoxk has been associated with XMRig-based Monero mining, Gh0st RAT, and BillGates malware variants used for DDoS activity. Supporting scripts were used to kill competing high-CPU processes, likely to maximize mining efficiency and maintain control of compromised hosts. Reporting also linked the cluster to Android malicious APK activity and to code associated with DSL/Nitol. The overall tradecraft reflects a financially motivated, multi-purpose intrusion set focused on monetizing compromised infrastructure through cryptomining while also leveraging botnet capabilities for denial-of-service attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.