Godzilla Backdoor Exploiting Confluence Vulnerability (Campaign)
ID: 17e6f7ee-5f11-50b6-92bf-10e5cd161ce6
STIX ID: report--17e6f7ee-5f11-50b6-92bf-10e5cd161ce6
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-08-30
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers discovered active exploitation of CVE-2023-22527 against Atlassian Confluence Data Center and Server, delivering a fileless in-memory backdoor dubbed "Godzilla" that uses AES-encrypted communications and injects a custom Tomcat valve to achieve unauthenticated remote code execution (CVSS 10). The backdoor resides entirely in memory and is difficult to detect; the report advises searching for indicators of compromise, removing identified files, and redeploying workloads from a known clean state.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
