logo

Stealth Bomber: Atlassian Confluence Exploits Drop Web Shells In-Memory

ID: 5474e121-fd9e-5736-9afa-3d35802c77df

STIX ID: report--5474e121-fd9e-5736-9afa-3d35802c77df

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-03-08

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

Researchers report active, in-the-wild exploitation of Atlassian Confluence CVE-2023-22527: attackers are using multiple PoCs (including 30 tracked variants) to achieve remote code execution, commonly deploying the Godzilla web shell and newer in-memory web-shell techniques that avoid disk artifacts and increase stealth; unpatched Confluence instances face high compromise risk and defenders are urged to patch, restrict Internet exposure (e.g., behind VPN), and improve network- and memory-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.