8220 Gang, also known as Water Sigbin and 8220, is a financially motivated, China-linked intrusion set focused primarily on opportunistic cryptojacking and related monetization activity. The group has been active since at least 2017 and is known for targeting exposed, vulnerable internet-facing infrastructure across both Windows and Linux environments, with a strong emphasis on cloud and web application servers. Reported victim sectors and geographies are broad, reflecting largely indiscriminate target selection rather than tightly scoped espionage objectives. The actor is best known for exploiting public-facing application vulnerabilities to gain initial access and execute remote commands. Recurrently abused products and flaws include Oracle WebLogic Server, Atlassian Confluence, Apache Log4j/Log4Shell, VMware Horizon, Hadoop YARN, Drupal, Apache Struts2, and JBoss-related services. Observed exploitation includes multiple WebLogic vulnerabilities such as CVE-2017-3506, CVE-2017-10271, CVE-2019-2725, CVE-2020-14882, CVE-2020-14883, and CVE-2023-21839, as well as CVE-2021-44228, CVE-2021-26084, and CVE-2022-26134. The group has repeatedly adapted older but still widely exposed vulnerabilities for mass exploitation. 8220 Gang commonly deploys cryptocurrency miners, especially XMRig-derived payloads and the PwnRig miner, and has also delivered additional malware including Tsunami, AgentTesla, rhajk, nasqa, ScrubCrypt, Hadooken, and K4Spreader. Tsunami provides IRC-based botnet and DDoS capability, while K4Spreader and Hadooken function as Linux-focused loaders and spreaders that establish persistence, disable defenses, remove competing malware, and install miners and backdoors. K4Spreader in particular has been observed using persistence through shell profile modification, cron jobs, init scripts, and systemd services, alongside firewall weakening, preload clearing, and host cleanup to retain control and maximize mining profitability. Tradecraft is centered on scalable exploitation and resilient payload delivery rather than stealthy long-term espionage. Across campaigns, the actor has used PowerShell, shell scripts, Python, Java-based exploit chains, custom downloaders, and staged loaders. Defensive evasion has included obfuscated scripts, layered base64 encoding, compressed and encrypted payloads, modified packers, AMSI bypasses, environment-variable-based batch obfuscation, reflective .NET loading, process injection, process hollowing, scheduled-task persistence, and abuse of legitimate processes for execution. On Linux and in containerized environments, the group has been observed disabling cloud security tooling, altering SELinux-related settings, manipulating cron, deleting logs, brute-forcing SSH for lateral movement, and killing rival miners or other malware. The actor has shown particular interest in cloud-hosted and containerized infrastructure, including Oracle Cloud and misconfigured Docker environments, where compromised compute resources can be monetized through illicit mining. Campaigns are frequently opportunistic and internet-scale, with little evidence of victim-specific reconnaissance before exploitation. The group has targeted both Linux and Windows web servers and has been observed adapting delivery methods to the operating system, using shell-based tooling on Linux and PowerShell-heavy chains on Windows. Attribution to 8220 Gang is supported by recurring overlaps in tooling, infrastructure patterns, payload families, infection routines, and monetization artifacts across campaigns. Some reporting also uses wallet reuse as a supporting signal, though that alone is not definitive. Overall, 8220 Gang is best characterized as a persistent, evolving cryptomining threat actor that continuously refreshes its loaders, spreaders, and evasion methods while exploiting exposed enterprise and cloud services at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Water Sigbin exploited the vulnerabilities CVE-2017-3506 and CVE-2023-21839 to deploy a cryptocurrency miner via a PowerShell script... We found the threat actor exploiting vulnerabilities with Oracle WebLogic server CVE-2017-3506 (a vulnerability allowing remote OS command execution)...
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability...
In November 2017, it used the Weblogic deserialization vulnerability (CVE- 2017-10271) invading a server and implanting a mining Trojan.
Currently, there are few samples and the following vulnerabilities are exploited. CVE_2020_14882
The group targets not only global systems but also Korean ones. ASEC has introduced a case where the attack group abused the Atlassian Confluence server vulnerability CVE-2022-26134 to attack Korean systems and install CoinMiner.
1 more CVE tied to this actor tracked in Mallory.
29 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Opportunistic cloud-focused intrusion set exploiting Oracle WebLogic vulnerabilities to compromise Windows and Linux cloud servers, disable security tooling, spread laterally via SSH brute force, establish persistence (cron/systemd), and deploy Monero cryptominers; also deploys the Tsunami IRC-controlled backdoor for botnet/DDoS capability.
Water Sigbin is known for exploiting Oracle WebLogic vulnerabilities to deploy cryptocurrency miners, specifically using a sophisticated multi-stage, fileless malware delivery chain that leverages reflective DLL injection, process injection, and anti-debugging techniques. The group primarily deploys the PureCrypter loader and XMRig miner, focusing on evasion and persistence.
China-origin cryptomining-focused threat group active since 2017 that compromises Windows/Linux servers by exploiting server-side RCE/unauthorized access flaws, establishes persistence, disables defenses, and deploys additional payloads including miners (PwnRig/XMRig-derived) and DDoS botnet malware (Tsunami). In this report, it is developing and deploying a new installer/downloader tool ('k4spreader') to spread and manage these payloads.
China-based threat actor active since at least 2017 that focuses on deploying cryptocurrency-mining malware, primarily in cloud-based environments and Linux servers, and in this campaign exploited Oracle WebLogic vulnerabilities to deliver a miner while using layered obfuscation and fileless execution techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.