z0Miner is a financially motivated cryptomining operation and associated malware family active since 2020. It compromises vulnerable Windows and Linux servers to deploy XMRig for unauthorized Monero mining. Its targets include Oracle WebLogic, Atlassian Confluence, Apache ActiveMQ, Elasticsearch, Jenkins, and deployments affected by Log4j vulnerabilities. Exploited vulnerabilities include CVE-2020-14882 and CVE-2020-14883 in WebLogic, CVE-2021-26084 in Confluence, CVE-2023-46604 in ActiveMQ, and CVE-2015-1427 in Elasticsearch. Activity observed in January 2024 included compromises of WebLogic servers in South Korea and the use of compromised Korean web servers as malware distribution infrastructure. The operation deploys JSP File Browser, Shack2, and Behinder web shells for persistent access, file management, and command execution. It also uses Fast Reverse Proxy to support RDP connectivity, Netcat reverse shells, and AnyDesk for remote access. Payload delivery uses PowerShell and Certutil on Windows and curl on Linux, with operating-system checks selecting platform-specific components. Persistence mechanisms include WMI event subscriptions, Windows scheduled tasks, and Linux cron jobs. Mining payloads remove competing miners, clean up earlier components, and hide downloaded files. The operators' country of origin is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The threat actor used WebLogic vulnerabilities such as CVE-2020-14882 to upload JSP WebShell.
This threat actor is well-known for using CVE-2020-14882 and CVE-2020-14883 vulnerabilities to attack WebLogic servers.
In the case of the Apache ActiveMQ vulnerability (CVE-2023-46604), the threat actor installed Netcat and additionally installed AnyDesk.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromises vulnerable servers to deploy XMRig for Monero mining, establish persistent remote access, and repurpose compromised Korean web servers as malware download infrastructure. The reported WebLogic attacks used multiple JSP web shells, FRP, and Netcat; a previous ActiveMQ exploitation case also involved AnyDesk. The content does not establish ransomware deployment or information theft by this group.
Actively exploiting Atlassian Confluence CVE-2021-26084 to deploy XMRig cryptocurrency miners on vulnerable Windows and Linux servers, using OS detection, downloader/dropper scripts, persistence mechanisms, and cleanup scripts. The content also links the group to earlier exploitation of Oracle WebLogic, Elasticsearch, and Jenkins RCE flaws for cryptomining.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.