rhajk is a malware family observed in attack campaigns attributed to the financially motivated 8220 gang. In the provided reporting, it is described alongside AgentTesla and nasqa as malware deployed after successful exploitation of Oracle WebLogic Server vulnerabilities CVE-2020-14883 and CVE-2020-14882, including via maliciously crafted XML files that enable remote code execution. The broader 8220 gang activity is associated with mass deployment of cryptojacking malware on Windows and Linux web servers, and FortiGuard specifically characterizes the post-exploitation payload set as including stealer and cryptominer malware such as AgentTesla, rhajk, and nasqa. The group uses different delivery methods depending on the target operating system, including cURL, wget, lwp-download, python urllib, and custom bash functions for Linux targets, and PowerShell WebClient commands for Windows targets; downloaded files are then executed on compromised hosts. Campaigns linked to this activity have targeted sectors including healthcare, telecommunications, and financial services, with observed victims in the United States, South Africa, Spain, Columbia, and Mexico. High-confidence indicators in the provided content are limited to the malware name rhajk and its association with 8220 gang WebLogic exploitation campaigns and co-deployment with AgentTesla and nasqa; no family-specific technical indicators or standalone behavioral details for rhajk are provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptominer payload deployed post-exploitation of Oracle WebLogic Server (CVE-2020-14883/CVE-2020-14882).
rhajk is a malware variant deployed by the 8220 gang in their campaigns, though specific details about its functionality are not provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.