Threat Advisory

z0Miner APT Deployed Malware Through Web Server Hijacking

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

The threat actor known as "z0miner" has been identified targeting Korean WebLogic servers, leveraging a history of exploiting vulnerabilities in various systems such as Atlassian Confluence, Apache ActiveMQ, and Log4j. Initially discovered by researchers, z0miner gained notoriety for exploiting CVE-2020-14882 and CVE-2020-14883 against Oracle WebLogic servers. However, recent findings by researchers reveal a shift towards Korean WebLogic servers, indicating a pattern of exploiting poor security configurations and widespread exposure of server information.[/subscribe_to_unlock_form]

Summary:

The threat actor known as "z0miner" has been identified targeting Korean WebLogic servers, leveraging a history of exploiting vulnerabilities in various systems such as Atlassian Confluence, Apache ActiveMQ, and Log4j. Initially discovered by researchers, z0miner gained notoriety for exploiting CVE-2020-14882 and CVE-2020-14883 against Oracle WebLogic servers. However, recent findings by researchers reveal a shift towards Korean WebLogic servers, indicating a pattern of exploiting poor security configurations and widespread exposure of server information.[emaillocker id="1283"]

The attack methodology employed by z0miner involves the deployment of multiple tools and techniques for exploitation. Firstly, utilizing the WebLogic vulnerability CVE-2020-14882, the threat actor uploads JSP webshells onto vulnerable systems, enabling persistent control. Notably, anti-malware products failed to detect these webshells, indicating their sophistication. Additionally, z0miner utilizes tools such as Fast Reverse Proxy (FRP) for Remote Desktop Communication (RDP) protocol communication, with both default and customized versions employed for connection attempts. NetCat, capable of reading and writing data over network connections, is also leveraged to bypass firewalls and gain control over targeted systems. Furthermore, the deployment of XMRig miners, tailored for Windows and Linux systems, enables the threat actor to establish persistence through Task Scheduler or WMI event filters, executing PowerShell scripts retrieved from specific Pastebin addresses. The utilization of Monero Wallet and Mining Pool addresses underscores the financial motive behind the attacks, while AnyDesk is selectively employed in conjunction with the Apache ActiveMQ vulnerability (CVE-2023-46604) exploitation.

The recent targeting of Korean WebLogic servers by the z0miner threat actor underscores the evolving nature of cyber threats and the need for robust security measures. Exploiting vulnerabilities in widely used systems and leveraging sophisticated tools like webshells, FRP, and XMRig miners, z0miner demonstrates a persistent and adaptable approach to malicious activities. As organizations continue to grapple with securing their digital infrastructure, proactive measures such as regular vulnerability assessments, security patching, and network monitoring are crucial to mitigating the risks posed by such threat actors.

Threat Profile:

References:

The following reports contain further technical details:

https://cybersecuritynews.com/hackers-deploy-z0miner-malware/

[/emaillocker]
crossmenu