K4Spreader is a Linux malware loader associated with the 8220 Gang, also known as Water Sigbin, and observed since February 2024. Implemented in Go with CGO components, it primarily deploys the Tsunami IRC-controlled backdoor and DDoS bot and the PwnRig Monero miner, an XMRig derivative. It can download and execute additional payloads, extract embedded executable payloads, and update itself. Some variants use modified UPX packing, including a version with two packing layers, while other observed samples are unobfuscated. Newer variants retrieve tasking as Base64-encoded, gzip-compressed JSON.
K4Spreader establishes persistence through shell-profile modifications, cron jobs, SysVinit scripts, and systemd services. It uses filesystem immutability attributes to hinder removal, disables host firewalls and cloud security tools, clears dynamic-linker preload configuration, and terminates competing cryptominers. Its deployment chains also use shell scripts to identify SSH targets and attempt lateral propagation through SSH brute force.
Distribution occurs through exploitation of vulnerable server applications, including Oracle WebLogic, JBoss, and Hadoop YARN. Observed WebLogic campaigns have exploited CVE-2017-10271, CVE-2020-14882, and CVE-2020-14883. Targeting is opportunistic and includes cloud-hosted Linux servers, with resource hijacking for cryptocurrency mining as a principal objective. K4Spreader shares infection routines, payloads, and infrastructure with Hadooken, but the two are distinct malware variants. Remote-control and DDoS functionality in these deployments is provided by Tsunami rather than established as an intrinsic K4Spreader capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attacker primarily exploited the CVE-2020-14883 vulnerability, occasionally leveraging of CVE-2017-10271.
We observed two distinct exploitation attempts: one targeting Linux (m.xml) and another one targeting Windows (m1.xml).
Currently, there are few samples and the following vulnerabilities are exploited. CVE_2020_14882
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based malware used to compromise cloud servers via Oracle WebLogic exploitation, disable defenses, kill rival miners, propagate laterally using SSH brute force, and maintain persistence (cron jobs/systemd) to support Monero mining; also uses shared infrastructure to fetch scripts for persistence.
Mentioned only as a comparative example of malware known to create hidden files under /dev or /dev/shm.
Linux ELF installer/loader (CGO/Go core) used by the 8220 mining gang to establish persistence (bash profile + init.d + systemd), self-update, disable firewall/iptables, remove competing malware processes/cron entries, and download/execute additional payloads. It deploys Tsunami (DDoS botnet) and PwnRig (Monero miner) either by downloading from C2 or extracting embedded payloads. Newer versions standardize C2 tasking via base64+gzip JSON.
Go-based malware deployed in a WebLogic exploitation campaign attributed to 8220 Gang. It disables cloud security mechanisms, terminates competing cryptominers, deploys Tsunami and PwnRig, and establishes persistence through cron jobs. It shares infrastructure and functionality with Hadooken, but the report treats them as distinct variants whose exact relationship remains unresolved.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.