Also known as: 8220 Gang, 8220, the 8220 Gang, APT10, Bronze Riverside, Cicada, Earth Tengshe, MirrorFace, Potassium, Venom Spider, DEV-0322 by Microsof, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, STONE PANDA, Menupass Team, happyyongzi, POTASSIUM, Red Apollo, CVNX, HOGFISH, Cloud Hopper, BRONZE RIVERSIDE, ATK41, G0045, Granite Taurus, TA429, Purple Typhoon
The 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware. They exploit vulnerabilities in Oracle WebLogic servers, such as CVE-2017-3506 and CVE-2023-21839, to deliver cryptocurrency miners using PowerShell scripts. The group has demonstrated a sophisticated multistage loading technique to deploy the PureCrypter loader and XMRIG crypto miner. They are known for using obfuscation techniques, such as hexadecimal encoding and code obfuscation, to evade detection and compromise systems.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Water Sigbin (8220 Gang) is a sophisticated cyber threat actor known for deploying cryptocurrency-mining malware through exploitation of Oracle WebLogic vulnerabilities like CVE-2017-3506 and CVE-2023-21839. Their primary activity involves using multistage techniques to deploy miners such as PureCrypter and XMRIG, employing obfuscation and evasion tactics.
Goals & Targeting
Their strategic focus is exploiting server environments for sustained crypto-mining operations to generate revenue. This targeting approach leverages high-value assets with minimal operational disruption, aiming for sectors with significant compute resources and less active monitoring of such vulnerabilities.
Enhanced Description
Water Sigbin is a cybercriminal group specializing in cryptojacking via server compromises. They exploit known vulnerabilities in Oracle WebLogic servers, delivering payloads through PowerShell scripts. Their multistage deployment involves using PureCrypter loader to inject XMRIG miners, with techniques like hexadecimal encoding and obfuscation to avoid detection. This group targets industries reliant on exposed WebLogic servers, focusing on critical infrastructure, financial services, and technology companies.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Water Sigbin has demonstrated a consistent operational pattern, targeting servers since their first activity. Campaigns often involve prolonged persistence to maximize mining output. Their use of multistage loaders enhances campaign sustainability against detection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in TTPs based on their consistent exploitation and obfuscation techniques. Some uncertainty remains about the group's exact motivation beyond financial gain and whether they operate with state-sponsored backing or solely as a cybercriminal organization.
No campaigns linked yet.
No observed data linked yet.
24
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics