logo

Confluence to Cerber: Exploitation of ​​CVE-2023-22518 for Ransomware Deployment

ID: 02c31c11-9f52-543a-9c9f-2322675010e0

STIX ID: report--02c31c11-9f52-543a-9c9f-2322675010e0

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress observed active exploitation of Confluence CVE-2023-22518 beginning Nov 3, 2023: attackers used an unauthenticated exploit (POST to /json/setup-restore.action with X-Atlassian-Token:no-check) to run an encoded PowerShell downloader that retrieved a Cerber-family ransomware binary (SHA256 f2e17ec85c3f8ee26a3be3ce52c6e140448941d705a9bdedb7c1aa82a9d9707f) from hXXp://193.176.179.41, which encrypts files with a L0CK3D suffix; the report provides IOCs, exploitation mechanics, and remediation guidance (patching, reducing external exposure, and defense-in-depth).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.