8220 Gang: Unleashing Malware through Oracle WebLogic Server Vulnerability

December 19, 2023
1 min read

The 8220 Gang, a threat actor group, has been exploiting a vulnerability in Oracle WebLogic Server to spread malware. The vulnerability, known as CVE-2020-14883, is a high-severity flaw that allows authenticated attackers to execute code on susceptible servers. The group has a history of leveraging security flaws to distribute cryptojacking malware and has previously targeted Oracle WebLogic servers. Recent attack chains observed by security researchers involve the exploitation of CVE-2020-14883 to deploy stealer and coin mining malware. The group targets various industries and countries, including healthcare, telecommunications, and financial services sectors in the U.S., South Africa, Spain, Columbia, and Mexico. Although considered unsophisticated, the group constantly evolves its tactics to evade detection.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is