8220 Gang, also known as 8220 and Water Sigbin, is a China-based, financially motivated cybercriminal group active since at least 2017. Its primary activity is cryptojacking: compromising servers and cloud infrastructure to mine cryptocurrency, particularly Monero, using victims’ computing resources. The group opportunistically targets Windows and Linux servers, exposed container environments, and vulnerable internet-facing applications. Documented victims include organizations in South Korea, the United States, South Africa, Spain, Colombia, and Mexico, with targeting spanning energy, healthcare, telecommunications, financial services, and cloud hosting environments. Initial access commonly involves exploitation of known vulnerabilities in Oracle WebLogic Server, Atlassian Confluence, Apache Log4j, Apache Struts, and other server applications, alongside abuse of misconfigured Docker daemons. Exploited vulnerabilities include CVE-2017-3506, CVE-2020-14882, CVE-2020-14883, CVE-2021-44228, CVE-2022-26134, and CVE-2023-21839. The group uses network scanning, SSH brute force, and harvested SSH keys and connection information to discover and compromise additional hosts. Its tooling includes XMRig and the XMRig-derived PwnRig miner, the Hadooken and K4Spreader malware variants, ScrubCrypt, PureCrypter, and the Tsunami IRC backdoor and DDoS bot. Windows attack chains employ obfuscated PowerShell, encrypted multistage payloads, reflective .NET loading, process hollowing and injection, DLL sideloading, and UAC bypass. Defense evasion includes AMSI and ETW patching, antivirus exclusions, anti-debugging checks, and fileless execution. Linux payloads disable firewalls and cloud security agents, alter security settings, erase logs, and terminate competing miners. Persistence mechanisms include cron jobs, scheduled tasks, startup entries, and system services. Some campaigns also deploy information-stealing malware and transmit host and user information to command-and-control infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Through a meticulously orchestrated operation, the group has been exploiting well-known vulnerabilities, including CVE-2021-44228 and CVE-2022-26134, underscoring a persistent threat to cloud environments worldwide.
In a recent campaign, the gang exploited vulnerabilities CVE-2017-3506 and CVE-2023-21839 to deploy a cryptocurrency miner via a PowerShell script.
Through a meticulously orchestrated operation, the group has been exploiting well-known vulnerabilities, including CVE-2021-44228 and CVE-2022-26134, underscoring a persistent threat to cloud environments worldwide.
The attacker primarily exploited the CVE-2020-14883 vulnerability, occasionally leveraging of CVE-2017-10271.
In a recent campaign, the gang exploited vulnerabilities CVE-2017-3506 and CVE-2023-21839 to deploy a cryptocurrency miner via a PowerShell script.
2 more CVEs tied to this actor tracked in Mallory.
98 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another intrusion set previously reported using PureCrypter.
Opportunistic cloud-focused intrusion set exploiting Oracle WebLogic vulnerabilities to compromise Windows and Linux cloud servers, disable security tooling, spread laterally via SSH brute force, establish persistence (cron/systemd), and deploy Monero cryptominers; also deploys the Tsunami IRC-controlled backdoor for botnet/DDoS capability.
A financially motivated, China-based threat actor active since 2017 that deploys cryptocurrency-mining malware, primarily targeting cloud environments and Linux servers. The described campaign exploits application vulnerabilities to deliver a miner through obfuscated scripts and uses in-memory execution to evade disk-based detection.
Water Sigbin is known for exploiting Oracle WebLogic vulnerabilities to deploy cryptocurrency miners, specifically using a sophisticated multi-stage, fileless malware delivery chain that leverages reflective DLL injection, process injection, and anti-debugging techniques. The group primarily deploys the PureCrypter loader and XMRig miner, focusing on evasion and persistence.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.