Attackers Exploit Critical Atlassian Confluence Flaw for Cryptojacking
ID: d410f26e-6cba-5b59-922c-0dca4dda3736
STIX ID: report--d410f26e-6cba-5b59-922c-0dca4dda3736
Feed Name: Dark Reading
Date Published: 2024-08-28
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro observed active exploitation of Atlassian Confluence CVE-2023-22527 (CVSS 10.0) in cryptojacking campaigns where attackers achieve unauthenticated RCE to deploy XMRig miners (via ELF payloads or SSH-delivered shell scripts), kill competing miners, disable cloud security (e.g., Alibaba Cloud Shield), gather credentials and IPs for SSH lateral movement, and maintain persistence through cron jobs; defenders are urged to patch, segment networks, and perform audits and incident response planning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
