Port 22

8220 Gang Exploiting Oracle WebLogic Flaw to Hijack Servers and Mine Cryptocurrency

The notorious cryptojacking group tracked as8220 Ganghas been spotted weaponizing a six-year-old security flaw in Oracle WebLogic servers to ensnare vulnerable instances into a botnet and distribute cryptocurrency mining malware. The flaw in question isCVE-2017-3506(CVSS score: 7.4), which, when successfully exploited, could allow an unauthenticated attacker to execute arbitrary commands