Confluence Exploit Leads to LockBit Ransomware
ID: 1d57af87-83ac-5076-ade0-ebd5cc7d6f78
STIX ID: report--1d57af87-83ac-5076-ade0-ebd5cc7d6f78
Feed Name: The DFIR Report
Threat Score
A Confluence server was exploited via CVE-2023-22527 to obtain SYSTEM access and deploy a Metasploit meterpreter and AnyDesk; the actor harvested credentials with Mimikatz, moved laterally via RDP, exfiltrated data to MEGA using Rclone, and rapidly (≈2 hours) deployed LockBit ransomware across the environment using manual execution and PDQ Deploy, leaving ransom notes and altered desktop backgrounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
