Water Sigbin is a threat actor group exploiting Oracle WebLogic vulnerabilities to deploy cryptocurrency-mining malware.
Analyst brief
Water Sigbin, also known as 8220 Gang, is a threat actor group deploying cryptocurrency-mining malware. They primarily target Oracle WebLogic servers by exploiting CVE-2017-3506 and CVE-2023-21839. Their key TTPs include PowerShell scripts, multistage loading, PureCrypter loader, XMRIG miner, and obfuscation techniques like hexadecimal encoding. Defenders should focus on patching Oracle WebLogic servers and enhancing monitoring for suspicious PowerShell execution and obfuscation attempts.
Water Sigbin
8220 Gang
unknown
The 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware. They exploit vulnerabilities in Oracle WebLogic servers, such as CVE-2017-3506 and CVE-2023-21839, to deliver cryptocurrency miners using PowerShell scripts. The group has demonstrated a sophisticated multistage loading technique to deploy the PureCrypter loader and XMRIG crypto miner. They are known for using obfuscation techniques, such as hexadecimal encoding and code obfuscation, to evade detection and compromise systems.