Hadooken is a Linux malware used in opportunistic intrusions against Oracle WebLogic and cloud-hosted environments to monetize compromised infrastructure. It has been associated with activity attributed to the 8220 Gang and is deployed after attackers gain access through weak credentials or by exploiting known WebLogic vulnerabilities such as CVE-2017-10271 and CVE-2020-14883. The malware is used primarily to hijack compute resources for cryptomining and is also linked to deployment of the Tsunami botnet malware to provide distributed denial-of-service capability and remote control of infected servers.
Observed intrusion chains use shell and Python scripts to install Hadooken, disable cloud protection tooling, terminate competing miners, search for SSH material, and propagate to additional systems through SSH brute-force and reuse of discovered access. Persistence is established through cron jobs, and operators have attempted to evade detection by disguising malicious services as legitimate processes and wiping logs after deployment. Activity has been concentrated in cloud and enterprise server environments, including exposed WebLogic infrastructure, with targeting noted across Asia and South America and substantial abuse of cloud-hosted systems.
Static analysis has identified code links between Hadooken and the RHOMBUS and NoEscape ransomware families, and related infrastructure has also been observed serving Mallox ransomware for Windows. However, confirmed observed use of Hadooken centers on Linux server compromise, persistence, lateral spread, cryptomining, and support for botnet-style DDoS operations rather than direct ransomware execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...two new malware variants, Hadooken and K4Spreader... target vulnerable cloud environments, primarily to hijack system resources for cryptomining."
"...two new malware variants, Hadooken and K4Spreader... target vulnerable cloud environments, primarily to hijack system resources for cryptomining."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...two new malware variants, Hadooken and K4Spreader... target vulnerable cloud environments, primarily to hijack system resources for cryptomining."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Hadooken, in turn, drops and executes a cryptominer and the Tsunami malware and then sets up multiple cron jobs with randomized names and payloads execution frequencies.
Hadooken, in turn, drops and executes a cryptominer and the Tsunami malware and then sets up multiple cron jobs with randomized names and payloads execution frequencies.
Aqua Security researchers highlight the practice of Hadooken renaining the malicious services as '-bash' or '-java', to mimic legitimate processes and blend with normal operations.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by the 8220 Gang to compromise vulnerable Oracle WebLogic servers (Windows and Linux), disable cloud protection tools, terminate competing miners, spread laterally (notably via SSH brute force), establish persistence, and deploy Monero cryptominers.
A newly reported Linux malware used against Oracle WebLogic servers. After compromise, it is dropped by shell/Python scripts, deploys a cryptominer and Tsunami, establishes persistence via cron jobs, disguises services as legitimate processes, wipes logs, and may provide access later leveraged for ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.