Confluence to Cerber: Exploitation of CVE-2023-22518 for Ransomware Deployment
ID: 02c31c11-9f52-543a-9c9f-2322675010e0
STIX ID: report--02c31c11-9f52-543a-9c9f-2322675010e0
Feed Name: Huntress Blog
Huntress observed active exploitation of Confluence CVE-2023-22518 beginning Nov 3, 2023: attackers used an unauthenticated exploit (POST to /json/setup-restore.action with X-Atlassian-Token:no-check) to run an encoded PowerShell downloader that retrieved a Cerber-family ransomware binary (SHA256 f2e17ec85c3f8ee26a3be3ce52c6e140448941d705a9bdedb7c1aa82a9d9707f) from hXXp://193.176.179.41, which encrypts files with a L0CK3D suffix; the report provides IOCs, exploitation mechanics, and remediation guidance (patching, reducing external exposure, and defense-in-depth).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
