Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Elliptic Report Shows How Bitcoin ATM Scams Move From Cash To On-Chain Wallets

July 27, 2026

382,000-Member Police Group Supports Revised Crypto CLARITY Act

July 27, 2026

The brutal $346M math behind Galaxy’s high-stakes race to build CoreWeave’s Texas AI mega-center

July 27, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»8220 Gang Behind ScrubCrypt Attack Targeting Oracle Weblogic Server
8220 Gang Behind ScrubCrypt Attack Targeting Oracle Weblogic Server
Security and Privacy

8220 Gang Behind ScrubCrypt Attack Targeting Oracle Weblogic Server

May 27, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

The threat actor known as “8220 Gang” has been associated with a new payload targeting an exploitable Oracle Weblogic Server in a specific Uniform Resource Identifier (URI).

The payload, analyzed by Fortinet security researchers, is characterized by the extraction of ScrubCrypt, a type of malware designed to obfuscate and encrypt applications with the goal of evading detection by security programs.

“We analyzed the malware injected into a victim’s system and, as part of our analysis, identified the threat actor as 8220 Gang using collected indicators,” wrote Fortinet senior antivirus analyst Cara Lin in Wednesday’s advisory.  “This mining group first appeared in 2017. The name ‘8220’ comes from its original use of port 8220 for network communications.”

According to Lin, ScrubCrypt has already been updated at least once. Its creators guarantee the malware can bypass Windows Defender and provide anti-debug and some bypass functions.

“We collected several ScrubCrypt samples in February, and each payload is a little different,” the malware analyst wrote, adding that the attacks observed by Fortinet occurred between January and February 2023.

Further, the security expert said that both the crypto wallet address used in these attacks and the server IP address used in Monero miner had been used by the 8220 Gang in the past, making the link to the threat group possible (despite the port number used for attacks no longer being 8220).

“8220 Gang is a well-known miner group that usually leverages public file-sharing websites and targets system vulnerabilities to infiltrate a victim’s environment,” Lin added.

“Within a very short time, it has evolved to use a newer crypter variant [that] includes evasion and encryption functions, making it harder for antivirus programs to detect 8220 Gang activity. Users should be aware of this updated crypter and keep their systems patched.”

See also  Crytocurrency Mining Soars 459% from 2017 to 2018

The threat actor’s activity was also observed by Microsoft last year, with the tech giant issuing a warning against the 8220 Gang in July 2022.

Editorial image credit: max.ku / Shutterstock.com

Source link

Attack Gang Oracle ScrubCrypt Server Targeting Weblogic
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

A Quantum Computer Could One Day Break Crypto Security — Coinbase Is Preparing Now

July 26, 2026

Triple-A Hot Wallets Drained of $9.7 Million Across Six Chains: Here’s What Peckshield Found

July 25, 2026

Two Ethereum bridges lose $31.7M within hours as third protocol halts staking

July 25, 2026

9 Wall Street and Crypto Giants Unite to Protect Bitcoin With $15 Million Initiative

July 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Grayscale’s GBTC Discount to NAV At Narrowest Since July 2021 on ETF Optimism

November 26, 2023

US Senator Cynthia Lummis Says SEC’s Decision To Sue Coinbase Is ‘Not the Right Way To Do Business in America’

June 23, 2023

ChatGPT and other AIs could play a big role in driving more users to crypto

May 20, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Elliptic Report Shows How Bitcoin ATM Scams Move From Cash To On-Chain Wallets

July 27, 2026

382,000-Member Police Group Supports Revised Crypto CLARITY Act

July 27, 2026

The brutal $346M math behind Galaxy’s high-stakes race to build CoreWeave’s Texas AI mega-center

July 27, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$64,968.001.20%
  • ethereumEthereum(ETH)$1,939.633.50%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$572.240.60%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.100.90%
  • solanaSolana(SOL)$76.162.40%
  • tronTRON(TRX)$0.3315440.10%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.032.90%
  • whitebitWhiteBIT Coin(WBT)$56.951.60%