logo

Attackers Exploit Critical Atlassian Confluence Flaw for Cryptojacking

ID: d410f26e-6cba-5b59-922c-0dca4dda3736

STIX ID: report--d410f26e-6cba-5b59-922c-0dca4dda3736

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-08-28

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro observed active exploitation of Atlassian Confluence CVE-2023-22527 (CVSS 10.0) in cryptojacking campaigns where attackers achieve unauthenticated RCE to deploy XMRig miners (via ELF payloads or SSH-delivered shell scripts), kill competing miners, disable cloud security (e.g., Alibaba Cloud Shield), gather credentials and IPs for SSH lateral movement, and maintain persistence through cron jobs; defenders are urged to patch, segment networks, and perform audits and incident response planning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.