Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Water Sigbin

Also known as: 8220 Gang, 8220, the 8220 Gang, APT10, Bronze Riverside, Cicada, Earth Tengshe, MirrorFace, Potassium, Venom Spider, DEV-0322 by Microsof, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, STONE PANDA, Menupass Team, happyyongzi, POTASSIUM, Red Apollo, CVNX, HOGFISH, Cloud Hopper, BRONZE RIVERSIDE, ATK41, G0045, Granite Taurus, TA429, Purple Typhoon

Description

The 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware. They exploit vulnerabilities in Oracle WebLogic servers, such as CVE-2017-3506 and CVE-2023-21839, to deliver cryptocurrency miners using PowerShell scripts. The group has demonstrated a sophisticated multistage loading technique to deploy the PureCrypter loader and XMRIG crypto miner. They are known for using obfuscation techniques, such as hexadecimal encoding and code obfuscation, to evade detection and compromise systems.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Energy
Telecommunications
Aerospace
Mining
Media
Education
Information technology
Maritime
Manufacturing
Think tank
Legal services
Healthcare
Pharmaceutical
Critical infrastructure
Chemical
Utilities
Hospitality
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
KR
IR
RU
SA
CA
TW
FR
KZ
IL
TR
AU
PK
VN
UA
PL
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

· 1 week ago

Executive Summary

Water Sigbin (8220 Gang) is a sophisticated cyber threat actor known for deploying cryptocurrency-mining malware through exploitation of Oracle WebLogic vulnerabilities like CVE-2017-3506 and CVE-2023-21839. Their primary activity involves using multistage techniques to deploy miners such as PureCrypter and XMRIG, employing obfuscation and evasion tactics.

Goals & Targeting

Their strategic focus is exploiting server environments for sustained crypto-mining operations to generate revenue. This targeting approach leverages high-value assets with minimal operational disruption, aiming for sectors with significant compute resources and less active monitoring of such vulnerabilities.

Enhanced Description

Water Sigbin is a cybercriminal group specializing in cryptojacking via server compromises. They exploit known vulnerabilities in Oracle WebLogic servers, delivering payloads through PowerShell scripts. Their multistage deployment involves using PureCrypter loader to inject XMRIG miners, with techniques like hexadecimal encoding and obfuscation to avoid detection. This group targets industries reliant on exposed WebLogic servers, focusing on critical infrastructure, financial services, and technology companies.

Key Capabilities

  • Exploitation of Oracle WebLogic vulnerabilities (CVE-2017-3506, CVE-2023-21839)
  • Multistage loader deployment
  • Hexadecimal encoding obfuscation techniques
  • PowerShell-based malware delivery
  • Persistence mechanisms

MITRE ATT&CK Tactics

Exploitation
Defense Evasion
Credential Access
Persistence
Execution

ATT&CK Techniques

T1064.001: Exploitation for Initial Access
T1205: Obfuscation via Encrypted Files/binaries/subprocessescripts
T1078: Valid Accounts Credential Access
T1053: Scheduled Task/Job Persistence
T1059.004: PowerShell Script Execution

Software / Tooling

PureCrypter Loader
XMRIG Miner
PowerShell Scripts
Hexadecimal Obfuscation Tools

Campaigns & Victims

Water Sigbin has demonstrated a consistent operational pattern, targeting servers since their first activity. Campaigns often involve prolonged persistence to maximize mining output. Their use of multistage loaders enhances campaign sustainability against detection.

IOC Patterns

  • Exploitation attempts against Oracle WebLogic
  • PowerShell scripts executing Base64/Hex encoded payloads
  • Presence of XMRIG miner processes
  • Scheduled tasks for persistence

Recommended Actions

  • Patch all Oracle WebLogic instances with available updates immediately.
  • Implement endpoint detection to monitor PowerShell and script activity.
  • Monitor network traffic for unusual patterns indicative of cryptojacking.

Suggested Tags

Cryptocurrency mining
Malware
Exploitation
Sustained Campaign

Confidence Assessment

High confidence in TTPs based on their consistent exploitation and obfuscation techniques. Some uncertainty remains about the group's exact motivation beyond financial gain and whether they operate with state-sponsored backing or solely as a cybercriminal organization.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 5 Filename 8 SHA-256 Hash 5 IPv4 Address 2

References

  1. thehackernews.com — Cited by web research for: APT10
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. www.trendmicro.com — Cited by web research for: T1190
  4. www.trendmicro.com — Cited by web research for: T1027.010

Intel Summary

24

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

Financial Targeting
Cryptocurrency mining
Malware
Exploitation
Sustained Campaign

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.