Confluence exploited for cryptojacking (Campaign)
ID: 9aaa0bdb-0abd-5699-b537-8fe6271f55da
STIX ID: report--9aaa0bdb-0abd-5699-b537-8fe6271f55da
Feed Name: Wiz Cloud Threat Landscape
Threat Score
Date Published: 2024-08-28
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
...
...
Active exploitation of CVE-2023-22527 in Atlassian Confluence Data Center and Server instances is being used for cryptojacking: attackers deploy shell scripts and XMRig miners, target SSH endpoints, kill competing mining processes, and maintain persistence via cron jobs; Atlassian released a January 16, 2024 advisory urging immediate updates to mitigage the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
