Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems
BI.ZONE links Feral Wolf ransomware attacks on Russian firms to Confluence CVE-2023-22515 exploitation and exposed 1C clusters, deploying GenieLocker.
BI.ZONE documented Feral Wolf ransomware intrusions against Russian retail, construction, manufacturing and IT organizations from May through August 2026. Attackers exploited CVE-2023-22515 on internet-facing Atlassian Confluence servers, abused unauthenticated 1C:Enterprise cluster management and debug modes to execute OS commands, and escalated from a restricted Docker container to the host via a weak-password PostgreSQL service. They used newly documented MQTTDoor and MatrixDoor backdoors, an RDP-tunneling proxy, credential harvesting from memory dumps, and the GenieLocker encryptor, blending C2 into legitimate protocols to evade detection.