8220 Gang, also known as Water Sigbin, is a financially motivated, China-linked intrusion set focused primarily on opportunistic cryptojacking and related monetization activity. Active since at least 2017, the group is known for mass exploitation of internet-exposed applications and cloud workloads, especially Oracle WebLogic, Atlassian Confluence, Apache Log4j/Log4Shell, VMware Horizon, Hadoop YARN, Drupal, and Apache Struts2. Its operations target both Windows and Linux systems, with a strong emphasis on vulnerable web servers and cloud-hosted environments. The actor’s core objective is hijacking victim compute resources for cryptocurrency mining, most commonly through XMRig-derived miners and the PwnRig miner. It has also deployed additional malware families including Tsunami, Hadooken, K4Spreader, AgentTesla, rhajk, nasqa, and ScrubCrypt. Tsunami provides IRC-based botnet functionality and DDoS capability, while K4Spreader and Hadooken act as Linux-focused installers and spreaders that establish persistence, disable defenses, remove competing malware, and deploy miners and botnet payloads. 8220 Gang commonly gains initial access by exploiting known remote code execution and authentication bypass vulnerabilities in public-facing services. Observed tradecraft includes PowerShell and shell-script downloaders, malicious XML payloads, Java-based exploitation chains, reflective .NET loading, in-memory execution, layered base64 and compression-based obfuscation, hexadecimal URL encoding, process hollowing, and process injection. On Windows, the group has used staged loaders and crypters to inject miners into legitimate processes, disable AMSI, add antivirus exclusions, and create scheduled tasks for persistence. On Linux, it has used cron jobs, init/systemd services, shell and Python scripts, SSH brute force, and modification of startup files to maintain access and spread laterally. The group also demonstrates defense evasion and post-exploitation behavior by disabling host firewalls and cloud security tooling, clearing preload-based hooks, deleting logs, killing rival miners, and removing competing persistence mechanisms. Campaigns against containerized and cloud environments have included targeting misconfigured Docker deployments and using brute-force tooling to expand access across internal networks. Targeting is broad and opportunistic rather than tightly scoped, but reported victims include cloud hosting environments, web infrastructure, healthcare, telecommunications, financial services, and energy-related organizations. Activity has been observed against targets in multiple countries, including South Korea, the United States, South Africa, Spain, Colombia, and Mexico. The actor is widely assessed as financially motivated, with cryptomining as its dominant objective, while some operations also incorporate botnet deployment and DDoS-enabling malware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Water Sigbin exploited the vulnerabilities CVE-2017-3506 and CVE-2023-21839 to deploy a cryptocurrency miner via a PowerShell script... We found the threat actor exploiting vulnerabilities with Oracle WebLogic server CVE-2017-3506 (a vulnerability allowing remote OS command execution)...
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability...
In November 2017, it used the Weblogic deserialization vulnerability (CVE- 2017-10271) invading a server and implanting a mining Trojan.
Currently, there are few samples and the following vulnerabilities are exploited. CVE_2020_14882
The group targets not only global systems but also Korean ones. ASEC has introduced a case where the attack group abused the Atlassian Confluence server vulnerability CVE-2022-26134 to attack Korean systems and install CoinMiner.
1 more CVE tied to this actor tracked in Mallory.
29 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Opportunistic cloud-focused intrusion set exploiting Oracle WebLogic vulnerabilities to compromise Windows and Linux cloud servers, disable security tooling, spread laterally via SSH brute force, establish persistence (cron/systemd), and deploy Monero cryptominers; also deploys the Tsunami IRC-controlled backdoor for botnet/DDoS capability.
Water Sigbin is known for exploiting Oracle WebLogic vulnerabilities to deploy cryptocurrency miners, specifically using a sophisticated multi-stage, fileless malware delivery chain that leverages reflective DLL injection, process injection, and anti-debugging techniques. The group primarily deploys the PureCrypter loader and XMRig miner, focusing on evasion and persistence.
China-origin cryptomining-focused threat group active since 2017 that compromises Windows/Linux servers by exploiting server-side RCE/unauthorized access flaws, establishes persistence, disables defenses, and deploys additional payloads including miners (PwnRig/XMRig-derived) and DDoS botnet malware (Tsunami). In this report, it is developing and deploying a new installer/downloader tool ('k4spreader') to spread and manage these payloads.
China-based threat actor active since at least 2017 that focuses on deploying cryptocurrency-mining malware, primarily in cloud-based environments and Linux servers, and in this campaign exploited Oracle WebLogic vulnerabilities to deliver a miner while using layered obfuscation and fileless execution techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.