Hadooken and K4Spreader: The 8220 Gang's Latest Arsenal
· Published 01/10/2024 10:08 · Modified 01/10/2024 10:21
Essential information
- Published
- 01/10/2024 10:08
- Modified
- 01/10/2024 10:21
- Tags
- 2024-10-01 CVE-2017-10271 CVE-2020-14883 botnet brazil china cryptomining hadooken k4spreader pwnrig tsunami weblogic
- Related entities
- 3 vulnerabilities (cve), 62 observables, 1 intrusion sets (apt), 17 techniques (mitre), 4 malware, 3 others
Description
This analysis uncovers a significant infection chain targeting Windows and Linux systems through Oracle WebLogic vulnerabilities. The attackers, likely the 8220 Gang, exploit CVE-2017-10271 and CVE-2020-14883 to deploy malware including K4Spreader, Tsunami backdoor, and cryptominers. The infection routine differs slightly between Windows and Linux systems but ultimately aims to mine Monero cryptocurrency. The campaign shares many similarities with the previously reported Hadooken case, including attack vectors, payloads, and infrastructure. Victim analysis reveals a focus on cloud environments, particularly in Asia and South America, with 200-250 compromised machines observed. The evolving tactics and global reach of the 8220 Gang highlight their ongoing threat to vulnerable cloud systems.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (3)
CVE-2020-14883
KEV
Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.
- Published
- 03/11/2021
- Modified
- 20/12/2025
CVE-2023-46604
KEV
10.0
Critical
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to …
- Attack vector
- Network
- Published
- 02/11/2023
- Modified
- 21/12/2025
CVE-2017-10271
KEV
7.5
High
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 19/10/2017
- Modified
- 22/04/2026
Observables (62)
80.78.24.3077.221.151.17477.221.149.21251.222.111.116157.230.29.135154.213.192.44198.199.85.23064.227.170.22751.255.171.23https://app.sekoia.io/intelligence/public/objects/indicator--fcc54a5a-3f13-4849-b48e-5197ab901324https://app.sekoia.io/intelligence/public/objects/indicator--f428ddd8-c478-4e9e-9ebe-03e99877ecfbhttps://app.sekoia.io/intelligence/public/objects/indicator--d618f9e9-321f-4762-a551-c9e8be60750ehttps://app.sekoia.io/intelligence/public/objects/indicator--bd31bdad-81aa-4b3d-82ab-8f48d7e2380ehttps://app.sekoia.io/intelligence/public/objects/indicator--b67815bd-0b13-4d33-a233-0fe38f4f1105https://app.sekoia.io/intelligence/public/objects/indicator--b4b3e913-a7e8-45e8-882e-48b3df13f4fehttps://app.sekoia.io/intelligence/public/objects/indicator--ae387077-65ff-4658-9631-af8dc6c12b35https://app.sekoia.io/intelligence/public/objects/indicator--ad184308-53e5-43e6-9011-dea3090ba3f8https://app.sekoia.io/intelligence/public/objects/indicator--a88b5a35-3390-4fe2-ba0c-ec1a14de842chttps://app.sekoia.io/intelligence/public/objects/indicator--a32e74b4-3694-4f22-b34e-1514b1dd23d9https://app.sekoia.io/intelligence/public/objects/indicator--9d2ed385-f34d-448f-9e92-055f8a515f25https://app.sekoia.io/intelligence/public/objects/indicator--9c694b52-bdb7-42ef-8874-4b343e4ac1c5https://app.sekoia.io/intelligence/public/objects/indicator--820de26f-69eb-4033-8bb4-87b515445a07https://app.sekoia.io/intelligence/public/objects/indicator--851e33a8-991c-4c2f-a876-2388812bc941https://app.sekoia.io/intelligence/public/objects/indicator--7c68157e-f858-46bd-8185-f18b9d46a85ahttps://app.sekoia.io/intelligence/public/objects/indicator--69493717-a478-4d03-9f6d-addb61651815https://app.sekoia.io/intelligence/public/objects/indicator--6a4b9f67-2c11-42e9-9aa9-91f3ecf67307https://app.sekoia.io/intelligence/public/objects/indicator--66d0b708-53b9-431f-bf73-d0eb1801b48bhttps://app.sekoia.io/intelligence/public/objects/indicator--5183d833-9391-42d1-b7fc-cae397867ba1https://app.sekoia.io/intelligence/public/objects/indicator--64e561ba-90fe-484f-97c1-9fe3cf23601ehttps://app.sekoia.io/intelligence/public/objects/indicator--45dc5b6d-e7ee-4b0c-85db-ff6225b98fcahttps://app.sekoia.io/intelligence/public/objects/indicator--3fc6a2e9-d67e-4cfa-a694-28572f7cc5dehttps://app.sekoia.io/intelligence/public/objects/indicator--30b7c383-00bb-41b7-9c88-48a6b4a85488https://app.sekoia.io/intelligence/public/objects/indicator--2cf6b8fe-fb64-40d8-bbe5-a25eb0f068cfhttps://app.sekoia.io/intelligence/public/objects/indicator--1e9facff-c79a-4ad1-8d6b-4b90a7666519https://app.sekoia.io/intelligence/public/objects/indicator--0e5acc4f-3df6-4dc0-aae2-f424bd1c3b76https://app.sekoia.io/intelligence/public/objects/indicator--027af819-1ef0-475d-a2cd-2b43357d554fhttps://app.sekoia.io/intelligence/public/objects/indicator--0217a6ba-d55b-436b-81d4-efe9d3279fcbhttp://154.213.192.44/yhttp://154.213.192.44/m1.xmlhttp://154.213.192.44/m.xmlhttp://154.213.192.44/gokuhttp://154.213.192.44/chttp://154.213.192.44/bin.ps1http://sck-dns.cc/chttp://51.222.111.116:80http://154.213.192.44/plugin3.dllhttp://154.213.192.44/Ueordwfkay.pdfirc.bashgo.pwplay.sck-dns.ccsck-dns.ccrun.on-demand.pwpwn.oracleservice.topc4k-ircd.pwndns.pwf6069886728686c5c6566c0332ba37c16805fb623b6fcbbd1dd2e09ee5cc75b1e68263fcc9b1f8729bba00f63fb5482f069218333a65cf1b0caa0fe6d7ce1ff3c964791501a48e919446892fe14ed101c27da375668ac7a24de891dc68356f9b9a5d68ca481091fbfde4d63087a836412bc8805b9a7cae000bd53899b0399e877b229b173b32cde47963de2a6e4bfcf243a8646fbf100fb2e379526b42ee45155100dbaf942556184928fc0387fb5aab69dc2ef7e77b29db75905329697f235011be73a9516ace88b1a0af52e4454f4bc1db514cc2511b3e02318bd8be2bcf0910c2913361debb5f1db95c170ce2d6892d598d97b9f1f7f76a8bc7b5053e801a1fcc2061f767574044ca1e97f92ca1d44ee0b35e0a796e3bd6a949ad4b1175e5
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 21:42 · Modified 20/12/2025 21:42
Techniques (MITRE) (17)
-
SSH
-
Brute Force
-
Remote System Discovery
-
Web Protocols
-
System Network Configuration Discovery
-
System Information Discovery
-
Ingress Tool Transfer
-
Resource Hijacking
-
Create or Modify System Process
-
System Services
-
Masquerading
-
Obfuscated Files or Information
-
Scheduled Task/Job
-
Exploit Public-Facing Application
-
External Remote Services
-
Valid Accounts
-
Command and Scripting Interpreter
Malware (4)
-
FamilyPublished 01/10/2024 10:08 · Modified 01/10/2024 10:08
-
FamilyPublished 01/10/2024 10:08 · Modified 01/10/2024 10:08
-
FamilyPublished 01/10/2024 10:08 · Modified 01/10/2024 10:08
-
FamilyPublished 14/04/2026 08:54 · Modified 14/04/2026 08:54
Others (3)
- China
- Brazil
- Technology