Microsoft Warns of '8220 Group' Targeting Linux Servers
... [T]he names of the group come from the port number 8220 used by the miner to communicate with the C2 servers....
https://www.cysecurity.news/2022/07/microsoft-warns-of-8220-group-targeting.html
How is this malware acquired?
Step 1: Stand up a C2 server.
Step 2: Doesn't matter unless you've stood up a C2 (command & control) server.
so i would have to run a server in order to get it? (I’m not real up on this stuff)