20/07/2022
Hacking & Cryptomining group 8220 on a spree - 'Extending its Botnets'
With the dip in the market value of cryptocurrencies, cryptojacking actors are now scaling up their operations to keep up with the previous profits.
Along with various other groups, The '8220', a crypto mining gang, is also scaling up their botnets by exploiting Linux and cloud app vulnerabilities, increasing the amount up to 30000 infected hosts.
This is a financially motivated group that targets publicly available systems running vulnerable versions of Docker, Redis, Confluence, and Apache and then infecting AWS, Azure, GCP, Alitun, and QCloud hosts.
The updates in its new script, used in expanding their botnet base, relate to:
1) A sufficiently stealthy piece of code even after lacking dedicated detection evasion mechanisms.
2) The use of block lists in the script to exclude specific hosts from infections, to avoid honeypots set up by security researchers
3) It now uses a new version of its custom cryptominer, PwnRig, which is based on the open-source Monero miner XMRig.
Let's Seecure the Internet - IOTrust Chain .
#8220