nasqa is malware observed in attack campaigns attributed to the financially motivated 8220 gang. In the provided reporting, it is identified alongside AgentTesla and rhajk as malware deployed after successful exploitation of Oracle WebLogic Server vulnerabilities CVE-2020-14883, often chained with CVE-2020-14882, using maliciously crafted XML files to achieve remote code execution. The broader activity is associated with opportunistic exploitation of internet-facing servers, particularly Windows and Linux web servers, and the actor has also been reported exploiting vulnerabilities in Atlassian Confluence and Apache Log4j in related campaigns. The 8220 gang is described as widely believed to be of Chinese origin and has targeted multiple industries including healthcare, telecommunications, and financial services across countries including the United States, South Africa, Spain, Colombia, and Mexico. The content explicitly characterizes the post-exploitation malware set as including stealer and cryptominer malware, but does not unambiguously specify which of those roles nasqa itself performs. No specific nasqa-only indicators of compromise, persistence mechanisms, or technical behaviors beyond its deployment in these campaigns are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...finally deploying stealer and cryptominer malware such as AgentTesla, rhajk, nasqa.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Payload referenced as part of a stealer/cryptominer set delivered after Oracle WebLogic exploitation (CVE-2020-14883/CVE-2020-14882).
nasqa is a malware variant deployed by the 8220 gang in their campaigns, though specific details about its functionality are not provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.