Water Sigbin

Aliases: 8220 Gang

First seen
2021-01-01 00:00:00
Origin
CN
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Last IoC activity
2026-04-18 02:09:36
Profile updated
2026-07-07 12:16:25

Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical

Context

The 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware. They exploit vulnerabilities in Oracle WebLogic servers, such as CVE-2017-3506 and CVE-2023-21839, to deliver cryptocurrency miners using PowerShell scripts. The group has demonstrated a sophisticated multistage loading technique to deploy the PureCrypter loader and XMRIG crypto miner. They are known for using obfuscation techniques, such as hexadecimal encoding and code obfuscation, to evade detection and compromise systems.

Exploited vulnerabilities

  • CVE-2017-3506 (vulnerability)
  • CVE-2022-26134 (vulnerability)
  • CVE-2023-21839 (vulnerability)

Reports & references

  • Trend Micro — Water Sigbin Xmrig (report)
  • Trend Micro — Decoding 8220 Latest Obfuscation Tricks (report)
  • uptycs.com — 8220 Gang Cryptomining Cloud Based Infrastructure Cyber Threat (report)
  • imperva.com — Imperva Detects Undocumented 8220 Gang Activities (report)
  • asec.ahnlab.com — 51568 (report)
  • Trend Micro — 8220 Gang Evolution New Strategies Adapted (report)
  • blog.aquasec.com — 8220 Gang Confluence Vulnerability Cve 2022 26134 (report)
  • sentinelone.com — From The Front Lines 8220 Gang Massively Expands Cloud Botnet To 30000 Infected Hosts (report)

External references