logo

Godzilla Backdoor Exploiting Confluence Vulnerability (Campaign)

ID: 17e6f7ee-5f11-50b6-92bf-10e5cd161ce6

STIX ID: report--17e6f7ee-5f11-50b6-92bf-10e5cd161ce6

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2024-08-30

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers discovered active exploitation of CVE-2023-22527 against Atlassian Confluence Data Center and Server, delivering a fileless in-memory backdoor dubbed "Godzilla" that uses AES-encrypted communications and injects a custom Tomcat valve to achieve unauthenticated remote code execution (CVSS 10). The backdoor resides entirely in memory and is difficult to detect; the report advises searching for indicators of compromise, removing identified files, and redeploying workloads from a known clean state.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.