logo

Where are they now? Starring: Confluence CVE-2023-22527

ID: c21e111b-f958-5b44-945c-8cd5944553be

STIX ID: report--c21e111b-f958-5b44-945c-8cd5944553be

Feed Name: GreyNoise Labs

Threat Score
75/100

Date Published: 2024-03-13

Date Updated: 2026-04-27

Author: Ron Bowes

...
...

A technical review of active exploitation of Atlassian Confluence CVE-2023-22527: observed POST requests (matching public Nuclei/Metasploit templates) deliver a bash loader (ldr.sh) that disables security tooling, tunes host settings for mining, downloads and runs a UPX-packed Go bitcoin miner, attempts SSH-based lateral propagation using harvested keys/hosts, and wipes logs; the report documents exploit samples, payload behavior, and indicators suggesting broad in‑the‑wild compromise risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.