Threat Advisory

New ScrubCrypt Crypter Used in Cryptojacking Attacks Targeting Oracle WebLogic

Threat: Malware
Threat Actor Name: 8220 Mining Group
Threat Actor Type: Financially Motivated
Targeted Region: Global
Alias: Returned Libra, 8220 Gang
Threat Actor Region: China
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

Summary:

A new crypter called ScrubCrypt has been used by the infamous bitcoin miner organization known as 8220 Gang to perform cryptojacking activities. The 8220 Gang's attacks were launched between November 2022 and January 2023 to break vulnerable Apache and Oracle WebLogic web servers and remove the XMRig miner. The organization discovered cryptojacking attacks that leverage malicious Microsoft Excel documents with VBA macros that are set up to download an executable to mine Monero (XMR) on compromised systems in late January 2023.[/subscribe_to_unlock_form]

Summary:

A new crypter called ScrubCrypt has been used by the infamous bitcoin miner organization known as 8220 Gang to perform cryptojacking activities. The 8220 Gang's attacks were launched between November 2022 and January 2023 to break vulnerable Apache and Oracle WebLogic web servers and remove the XMRig miner. The organization discovered cryptojacking attacks that leverage malicious Microsoft Excel documents with VBA macros that are set up to download an executable to mine Monero (XMR) on compromised systems in late January 2023.[emaillocker id="1283"]

 

 

ScrubCrypt is a crypter that secures apps using a special BAT packing technique. The attack chain starts when vulnerable Oracle WebLogic servers are successfully used to download a PowerShell script that contains ScrubCrypt. The crypters can modify, obfuscate, and encrypt malware with the purpose of preventing detection by security software. ScrubCrypt contains capabilities for bypassing Windows Defender security as well as checking for the presence of debugging and virtual machine environments. The backslash character, "" can be used to divide the encrypted data. The miner operation is started when the crypter decodes and loads the miner payload into memory in the final stage. In this attack tries to download a PowerShell file with its primary code and strings encoded to make it more difficult for AntiVirus to detect. Another Base64-encoded piece of code has been saved in the victim's temporary folder so it can appear to be a legitimate system file. After being decoded and stored, the fake "update" file operates with Windows-style hidden to discreetly load ScrubCrypt.

The well-known miner group 8220 Gang frequently uses open file-sharing services and focuses on system flaws to infiltrate a victim's environment. It quickly changed to utilize ScrubCrypt a more recent crypter variation. The ScrubCrypt has encryption and evasion features that make it more difficult for anti-virus software to identify 8220 Gang activity. Users should keep their systems patched and informed about this upgraded crypter.

 

Threat Profile:

Tactic Technique Id Technique
 Resource Development T1584 Compromise Infrastructure
 Initial Access T1189 Drive-by Compromise
Execution T1059 Command and Scripting Interprete
T1204 User Execution
 Defense Evasion T1027 Obfuscated Files or Information
T1562 Impair Defenses
T1055 Process Injection
T1036 Masquerading
 Command and Control T1132 Data Encoding
Exfiltration T1041 Exfiltration Over C2 Channel
 Impact T1496 Resource Hijacking

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/03/new-scrubcrypt-crypter-used-in.html

[/emaillocker]
crossmenu