8220 Gang Exploiting Oracle WebLogic Flaw to Hijack Servers and Mine Cryptocurrency
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-3506 | Unauthenticated OS Command Injection in Oracle WebLogic Server CVE-2017-3506 is an unauthenticated operating system command injection flaw (CWE-78) in the Web Services subcomponent of Oracle WebLogic Server. A remote attacker with network access over HTTP can trigger it, though the flaw is rated difficult to exploit (high attack complexity). Successful exploitation allows the attacker to create, delete, or modify critical data and gain unauthorized access to critical data — potentially all data accessible to WebLogic Server — without authentication, with no availability impact. Organizations running affected versions 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1, or 12.2.1.2 are exposed, especially where the HTTP interface is internet-reachable. The flaw is under active attack: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-03, EPSS is at 96.3%, and the 8220 gang is exploiting it to deliver infostealers and cryptocurrency miners. Do: Apply the Oracle Critical Patch Update from April 2017 or later (or upgrade WebLogic Server to a patched, supported release), consistent with CISA's KEV required action to apply vendor mitigations or discontinue use. Until patched, restrict network access to the Web Services HTTP interface. Hunt affected servers for 8220 gang activity — unexpected child processes, cryptomining loads, and infostealer artifacts — since exploitation requires no authentication. | 7.4 | 96% | KEV |
| largetens of thousands (≈10k–100k) of internet-exposed WebLogic servers; substantially more when internal enterprise deployments are counted |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | letmaker.top | r from one of the three C2 servers – 179.43.155[.]202, work.letmaker[.]top, and su-94.letmaker[.]top – using TCP ports 9090, 9091, o |
Full article531 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 18, 2023Cryptocurrency / Server Security
The notorious cryptojacking group tracked as 8220 Gang has been spotted weaponizing a six-year-old security flaw in Oracle WebLogic servers to ensnare vulnerable instances into a botnet and distribute cryptocurrency mining malware.
The flaw in question is CVE-2017-3506 (CVSS score: 7.4), which, when successfully exploited, could allow an unauthenticated attacker to execute arbitrary commands remotely.
"This allows attackers to gain unauthorized access to sensitive data or compromise the entire system," Trend Micro researcher Sunil Bharti said in a report published this week.
8220 Gang, first documented by Cisco Talos in late 2018, is so named for its original use of port 8220 for command-and-control (C2) network communications.
"8220 Gang identifies targets via scanning for misconfigured or vulnerable hosts on the public internet," SentinelOne noted last year. "8220 Gang is known to make use of SSH brute force attacks post-infection for the purposes of lateral movement inside a compromised network."
Earlier this year, Sydig detailed attacks mounted by the "low-skill" crimeware group between November 2022 and January 2023 that aim to breach vulnerable Oracle WebLogic and Apache web servers and deploy a cryptocurrency miner.
It has also been observed making use of an off-the-shelf malware downloader known as PureCrypter as well as a crypter codenamed ScrubCrypt to conceal the miner payload and evade detection by security software.
In the latest attack chain documented by Trend Micro, the Oracle WebLogic Server vulnerability is leveraged to deliver a PowerShell payload, which is then used to create another obfuscated PowerShell script in memory.
This newly created PowerShell script disables Windows Antimalware Scan Interface (AMSI) detection and launches a Windows binary that subsequently reaches out to a remote server to retrieve a "meticulously obfuscated" payload.
The intermediate DLL file, for its part, is configured to download a cryptocurrency miner from one of the three C2 servers – 179.43.155[.]202, work.letmaker[.]top, and su-94.letmaker[.]top – using TCP ports 9090, 9091, or 9092.
Trend Micro said recent attacks have also entailed the misuse of a legitimate Linux tool called lwp-download to save arbitrary files on the compromised host.
"lwp-download is a Linux utility present in a number of platforms by default, and 8220 Gang making this a part of any malware routine can affect a number of services even if it were reused more than once," Bharti said.
"Considering the threat actor's tendency to reuse tools for different campaigns and abuse legitimate tools as part of the arsenal, organizations' security teams might be challenged to find other detection and blocking solutions to fend off attacks that abuse this utility."
The development comes as Kaspersky disclosed a partial multi-step infection sequence that leveraged a PowerShell script to deploy a cryptocurrency miner dubbed Minas, which it said "uses a standard implementation and aims to hide its presence."
"The difficulty of detection is achieved due to encryption, the random generation of names and the use of hijacking and injection techniques. It also has the ability to stay on the infected system using persistence techniques," the Russian cybersecurity company added.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/05/8220-gang-exploiting-oracle-weblogic.html