8220 Gang Cloud Botnet Targets Misconfigured Cloud Workloads

8220 Gang continues to infect misconfigured cloud workloads by exploiting outdated Docker, Apache, WebLogic, and Log4J services and expanding its cryptocurrency-mining botnet. It rotates infrastructure, uses PureCrypter MaaS, and distributes miners via Discord links and a mining proxy to grow its network. #8220Gang #PureCrypter #CVE-2019-2725 #UbiquitiUniFi #LetmakerTop #OracleWebLogic #Discord

Keypoints

  • Misconfigured or vulnerable cloud services (e.g., Docker, Apache, WebLogic, Log4J) on AWS/Azure are the primary infection surface for 8220 Gang.
  • Attackers identify targets by scanning the public internet for exposed services like Docker, Confluence, Apache WebLogic, and Redis.
  • SSH brute force is used after infection to move laterally within compromised networks.
  • Cryptocurrency mining is the main objective, with new miners being deployed and botnets expanded where possible.
  • The group leverages PureCrypter MaaS to distribute loaders/miners, including C2 infrastructure and Discord-based delivery links.
  • Infrastructure is rotated (e.g., 89.34.27.167 → 79.110.62.23) and uses domains such as letmaker.top and oracleservice.top with a mining proxy to pool resources.

MITRE Techniques

  • [T1190] Exploit Public-Facing Application – ‘The vulnerabilities exploited are usually far from fresh – such as with CVE-2019-2725 – the Oracle Weblogic vulnerability being exploited to download the installer script.’
  • [T1021.004] SSH – ‘SSH brute force attacks post-infection for the purposes of lateral movement inside a compromised network.’
  • [T1496] Resource Hijacking – ‘beginning cryptomining on the victim host.’
  • [T1105] Ingress Tool Transfer – ‘The loader then beacons back following the injectors image extension URLs. The downloader then beacons back… and downloads …,’
  • [T1071.001] Application Layer Protocol – ‘The loader beacons to Discord: …miner_Nyrpcmbw.png’ and uses Discord as part of its delivery/payload workflow.
  • [T1587.001] Acquire Capabilities – ‘PureCrypter Malware-as-a-service… loader service available for a low cost since 2021’ to obtain tools for infection and deployment.

Indicators of Compromise

  • [IP Address] Communications – 89.34.27.167, 79.110.62.23, and 2 more IPs (e.g., 51.79.175.139, 198.23.214.117) used for control and mining proxy roles
  • [Domain] Communications – work.onlypirate.top, a.oracleservice.top, and 1–2 more domains (e.g., b.oracleservice.top, pwn.oracleservice.top)
  • [SHA1 Hash] Files – 871f38fd4299b4d94731745d8b33ae303dcb9eaa, ee6787636ea66f0ecea9fa2a88f800da806c3ea6, and 15 more hashes
  • [URL] Downloads/C2 Links – https://cdn.discordapp[.]com/attachments/994652587494232125/1004395450058678432/miner_Nyrpcmbw[.]png

Read more: https://www.sentinelone.com/blog/8220-gang-cloud-botnet-targets-misconfigured-cloud-workloads/