Where are they now? Starring: Confluence CVE-2023-22527
ID: c21e111b-f958-5b44-945c-8cd5944553be
STIX ID: report--c21e111b-f958-5b44-945c-8cd5944553be
Feed Name: GreyNoise Labs
A technical review of active exploitation of Atlassian Confluence CVE-2023-22527: observed POST requests (matching public Nuclei/Metasploit templates) deliver a bash loader (ldr.sh) that disables security tooling, tunes host settings for mining, downloads and runs a UPX-packed Go bitcoin miner, attempts SSH-based lateral propagation using harvested keys/hosts, and wipes logs; the report documents exploit samples, payload behavior, and indicators suggesting broad in‑the‑wild compromise risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
