Hadooken is a Go-based Linux malware dropper associated with the 8220 Gang that targets Oracle WebLogic servers and cloud-hosted environments. It deploys a Monero cryptominer and Tsunami, a Linux backdoor and DDoS bot that uses IRC for command and control. Its principal purpose is to monetize compromised computing resources through cryptomining while enabling botnet operations.
Hadooken is delivered through shell and Python scripts following server compromise, including observed access through weak credentials. Its infection chain searches for SSH connection information and uses SSH brute-force attacks to propagate to additional systems. It establishes persistence through multiple cron jobs, disguises malicious processes as legitimate shell or Java processes, disables cloud protection tools, and terminates competing miners. Deployment activity also includes clearing system logs to conceal the intrusion.
Hadooken shares infrastructure, deployment scripts, mining payloads, and propagation techniques with K4Spreader campaigns linked to the 8220 Gang. The two are distinct malware variants with similar functionality. Related campaigns exploit Oracle WebLogic vulnerabilities, including CVE-2017-10271 and CVE-2020-14883, to compromise resource-rich enterprise and cloud servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...two new malware variants, Hadooken and K4Spreader... target vulnerable cloud environments, primarily to hijack system resources for cryptomining."
"...two new malware variants, Hadooken and K4Spreader... target vulnerable cloud environments, primarily to hijack system resources for cryptomining."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A comparative analysis of Hadooken and K4Spreader suggests that they are two distinct Go-based malware variants with similar functionalities.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Hadooken, in turn, drops and executes a cryptominer and the Tsunami malware and then sets up multiple cron jobs with randomized names and payloads execution frequencies.
Hadooken, in turn, drops and executes a cryptominer and the Tsunami malware and then sets up multiple cron jobs with randomized names and payloads execution frequencies.
Aqua Security researchers highlight the practice of Hadooken renaining the malicious services as '-bash' or '-java', to mimic legitimate processes and blend with normal operations.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by the 8220 Gang to compromise vulnerable Oracle WebLogic servers (Windows and Linux), disable cloud protection tools, terminate competing miners, spread laterally (notably via SSH brute force), establish persistence, and deploy Monero cryptominers.
A newly reported Linux malware used against Oracle WebLogic servers. After compromise, it is dropped by shell/Python scripts, deploys a cryptominer and Tsunami, establishes persistence via cron jobs, disguises services as legitimate processes, wipes logs, and may provide access later leveraged for ransomware deployment.
Go-based malware deployed against WebLogic servers through shell and Python scripts. It installs PwnRig and Tsunami and establishes cron-based persistence. Shared scripts, infrastructure, payload hashes, and a Monero wallet strongly link its campaign to the K4Spreader operation and 8220 Gang.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.