The threat actor, who goes by the name “z0miner,” has been found to be attacking Korean WebLogic servers to distribute malware like miners, network tools, and scripts for attacking further.
This threat actor has a history of attacking vulnerable servers such as Atlassian Confluence, Apache ActiveMQ, Log4j, and many more.
Researchers at Tencent first discovered this threat actor in 2020. The “z0miner” threat actor is well-known for exploiting CVE-2020-14882 and CVE-2020-14883 against Oracle WebLogic servers.
However, according to ASEC researchers, their latest targets were Korean WebLogic servers, and several traces of tools such as FRP (Fast Reverse Proxy), NetCat, and AnyDesk were present.
Malware analysis can be fast and simple. Just let us show you the way to:
According to reports shared with Cyber Security News, the threat actor exploited these Korean WebLogic servers due to poor security configuration and the widespread exposure of server information.
The threat actor could discover the Tomcat version and server version of these servers.
Once this information was gathered, the threat actors used several tools, such as WebShell, FRP, and NetCat, to further exploit it.
The threat actor utilized the WebLogic vulnerability CVE-2020-14882 to upload a JSP webshell on the vulnerable system, enabling persistence and control over the system.
Three webshells, such as JSP file Browser, Shack2, and Behinder, were deployed. Moreover, none of these webshells were detected by anti-malware products.
This tool was used for RDP (Remote Desktop Communication) protocol communication. Additionally, both the default frpc as well as a customized version were used.
The default frpc loads a settings file in the *.INI form and attempts the connection, while the customized frpc can be run without using an individual file.
Netcat is capable of reading and writing data over a network connection and has been found in many webshells.
The tools provide a remote shell feature, which allows them to bypass the firewall and get control over the targeted system.
The versions of XMRig used by z0miner are different for Windows and Linux. XMRig 6.18.0 was used in Windows, and 6.18.1 was used for Linux.
To establish persistence with Miner, the threat actor used the Task Scheduler (schtasks) or WMI’s event filter and configured it to read a PowerShell script from a certain Pastebin address and execute it.
The threat actor also used the Monero Wallet and Mining Pool address.
AnyDesk was also one of the tools used by the threat actor as part of the webshell but only used in cases where the Apache ActiveMQ vulnerability (CVE-2023-46604) is exploited.
(Korean web servers exploited and used as download servers are shown only on TIP.)
With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.
Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…