Skip to main content
Mallory
MalwareUsed by 1 actorExploits 2 CVEs

Hadooken

Hadooken is a malware variant used by the China-based 8220 Gang to target vulnerable cloud environments and hijack system resources for cryptomining. It has been observed in opportunistic campaigns against both Windows and Linux systems, notably through exploitation of Oracle WebLogic vulnerabilities including CVE-2017-10271 and CVE-2020-14883. The infection chain uses WebLogic exploitation to execute scripts that download loaders and install cryptomining malware, with activity mirroring attack chains previously observed on WebLogic servers.

Hadooken shares infection routines and infrastructure with K4Spreader, suggesting both are operated by the same threat actor. Its behavior includes disabling cloud protection tools, terminating competing cryptominers on compromised hosts, and spreading laterally via SSH brute force. The attackers’ objective is to establish persistence and deploy cryptominers to mine Monero, including through a private mining pool. Shared infrastructure includes use of the sck-dns[.]cc domain to download a malicious script named "c" for persistence; mining-related infrastructure also includes run.on-demand[.]pw.

The broader intrusion chain associated with Hadooken has also involved delivery of the Tsunami backdoor, which provides remote control and botnet capability over IRC. The campaign is described as heavily focused on cloud hosting services, with many compromised IPs in Oracle Cloud and targeting concentrated in Asia and South America.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2017-10271Oracle WebLogic WLS-WSAT XML Deserialization RCE

"...two new malware variants, Hadooken and K4Spreader... target vulnerable cloud environments, primarily to hijack system resources for cryptomining."

via security online infosecurityonline.info
CVE-2020-14883Oracle WebLogic Server Console RCE via Authentication Bypass Chain

"...two new malware variants, Hadooken and K4Spreader... target vulnerable cloud environments, primarily to hijack system resources for cryptomining."

via security online infosecurityonline.info
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
8220 Gang

"...two new malware variants, Hadooken and K4Spreader... target vulnerable cloud environments, primarily to hijack system resources for cryptomining."

via security online infosecurityonline.info
INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
2 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 years ago
domain●●●●●●●●●●●●View more in app2 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.