8220 Gang, also known as Water Sigbin, is a financially motivated cryptojacking intrusion set widely assessed to be China-based and active since at least 2017. The group is known for opportunistic mass exploitation of internet-exposed servers and cloud workloads, especially Oracle WebLogic, Atlassian Confluence, Apache Log4j/Log4Shell, Apache Struts, Hadoop YARN, Drupal, exposed Docker daemons, and VMware Horizon. Its operations primarily aim to hijack compute resources for Monero mining, but the group has also deployed additional malware including the Tsunami/Kaiten IRC botnet for remote control and DDoS capability, as well as malware such as AgentTesla, rhajk, nasqa, Hadooken, K4Spreader, PureCrypter, ScrubCrypt, and PwnRig in observed campaigns. The actor targets both Linux and Windows environments, with a strong emphasis on cloud-hosted and web-facing infrastructure. Observed tradecraft includes exploitation of public-facing applications for initial access, PowerShell and shell-script execution, Python-based tooling, ingress tool transfer, layered obfuscation using Base64 and hexadecimal encoding, reflective loading and in-memory execution, process injection and process hollowing, scheduled tasks, cron jobs, init/systemd services, .bash_profile modification, and disabling or bypassing security controls. The group has repeatedly used persistence mechanisms across containerized and bare-metal environments, removed competing miners, altered firewall settings, cleared preload configurations, and attempted lateral movement through SSH key abuse and SSH brute force. Campaigns against exposed Docker environments and cloud servers have also shown reconnaissance, scanning, brute-force behavior, and post-exploitation actions to maximize resource theft. 8220 Gang has been observed exploiting Oracle WebLogic vulnerabilities including CVE-2017-3506, CVE-2017-10271, CVE-2020-14883 often with CVE-2020-14882, and CVE-2023-21839; Atlassian Confluence vulnerabilities including CVE-2019-3396 and CVE-2022-26134; Apache Struts CVE-2017-5638; and Log4Shell CVE-2021-44228. In VMware Horizon and WebLogic intrusions, the actor used multi-stage loaders and crypters to deploy XMRig-based miners while evading detection through AMSI bypass, anti-analysis checks, Windows Defender exclusions, and fileless execution. Linux-focused tooling such as K4Spreader and Hadooken has been used to establish persistence, fetch updated payloads, deploy miners, and install Tsunami for botnet functionality. Victimology is opportunistic rather than tightly scoped, but reporting links the actor to attacks on cloud hosting environments, web servers, healthcare, telecommunications, financial services, and energy-related organizations. Confirmed geographic targeting includes South Korea, and broader activity has been reported in the United States, South Africa, Spain, Colombia, and Mexico, with additional emphasis on Asia and South America in cloud-focused campaigns. The actor is generally characterized as a criminal cryptomining group rather than a state-directed espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Water Sigbin exploited the vulnerabilities CVE-2017-3506 and CVE-2023-21839 to deploy a cryptocurrency miner via a PowerShell script... We found the threat actor exploiting vulnerabilities with Oracle WebLogic server CVE-2017-3506 (a vulnerability allowing remote OS command execution)...
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability...
In November 2017, it used the Weblogic deserialization vulnerability (CVE- 2017-10271) invading a server and implanting a mining Trojan.
Currently, there are few samples and the following vulnerabilities are exploited. CVE_2020_14882
The group targets not only global systems but also Korean ones. ASEC has introduced a case where the attack group abused the Atlassian Confluence server vulnerability CVE-2022-26134 to attack Korean systems and install CoinMiner.
1 more CVE tied to this actor tracked in Mallory.
29 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another intrusion set previously reported using PureCrypter.
Opportunistic cloud-focused intrusion set exploiting Oracle WebLogic vulnerabilities to compromise Windows and Linux cloud servers, disable security tooling, spread laterally via SSH brute force, establish persistence (cron/systemd), and deploy Monero cryptominers; also deploys the Tsunami IRC-controlled backdoor for botnet/DDoS capability.
Water Sigbin is known for exploiting Oracle WebLogic vulnerabilities to deploy cryptocurrency miners, specifically using a sophisticated multi-stage, fileless malware delivery chain that leverages reflective DLL injection, process injection, and anti-debugging techniques. The group primarily deploys the PureCrypter loader and XMRig miner, focusing on evasion and persistence.
China-origin cryptomining-focused threat group active since 2017 that compromises Windows/Linux servers by exploiting server-side RCE/unauthorized access flaws, establishes persistence, disables defenses, and deploys additional payloads including miners (PwnRig/XMRig-derived) and DDoS botnet malware (Tsunami). In this report, it is developing and deploying a new installer/downloader tool ('k4spreader') to spread and manage these payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.