ZeroHour
Organization

BI.ZONE

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems

BI.ZONE links Feral Wolf ransomware attacks on Russian firms to Confluence CVE-2023-22515 exploitation and exposed 1C clusters, deploying GenieLocker.

BI.ZONE documented Feral Wolf ransomware intrusions against Russian retail, construction, manufacturing and IT organizations from May through August 2026. Attackers exploited CVE-2023-22515 on internet-facing Atlassian Confluence servers, abused unauthenticated 1C:Enterprise cluster management and debug modes to execute OS commands, and escalated from a restricted Docker container to the host via a weak-password PostgreSQL service. They used newly documented MQTTDoor and MatrixDoor backdoors, an RDP-tunneling proxy, credential harvesting from memory dumps, and the GenieLocker encryptor, blending C2 into legitimate protocols to evade detection.

Related CVEs

  • Unauthenticated Broken Access Control in Atlassian Confluence Data Center/Server
    Atlassian Confluence Data Center and Server contain a broken access control flaw (CWE-20) in publicly accessible instances that allows unauthenticated remote attackers to create unauthorized Confluence administrator accounts and gain access to the instance; the associated public PoC is titled 'Atlassian Confluence Unauthenticated Remote Code Execution'. The flaw is triggered over the network (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N) against any self-managed Confluence instance reachable from the internet, with no privileges or user interaction required. Attackers who exploit it gain administrator-level control of the Confluence instance, and the public PoC demonstrates this extends to unauthenticated code execution. Only self-managed Confluence Data Center and Server deployments are affected; Atlassian Cloud sites hosted on atlassian.net domains are not vulnerable. Exploitation is confirmed in the wild: CISA added it to the KEV on 2023-10-05 with known ransomware use, EPSS is 99.2%, Atlassian reported a handful of customers were already exploited, and Microsoft warned of nation-state (China-linked) abuse.
    · Atlassian Confluence Data Center · Atlassian Confluence Server KEV ransomware PoC large
  • Local Privilege Escalation (Copy Fail) in Linux Kernel algif_aead Interface
    CVE-2026-31431 ('Copy Fail') is an incorrect resource transfer between spheres (CWE-669/CWE-1288) in the Linux kernel's algif_aead implementation of the AF_ALG userspace crypto interface, introduced roughly nine years ago (around 2017, per public reporting) when commit 72548b093ee3 switched AEAD operations to in-place handling even though the source and destination buffers come from different mappings. A local, unprivileged user can trigger the flaw by performing AEAD operations through the AF_ALG socket interface, causing the kernel to mishandle the copy of ciphertext and associated data. Successful exploitation provides a reliable local privilege escalation to root (C:H/I:H/A:H per the CVSS vector). Nearly every major Linux distribution and enterprise platform is exposed, including the kernel itself, Red Hat Enterprise Linux (including AUS, EUS, TUS and Update Services for SAP Solutions), OpenShift Container Platform, Amazon Linux, Ubuntu, Debian, openSUSE Leap, SUSE CaaS Platform, NixOS, and Linux-based products from Arista and Siemens. The flaw has public proof-of-concept code, a 99.9% EPSS score, and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-01, indicating exploitation in the wild (ransomware use is unknown).
    · Linux kernel (algif_aead / AF_ALG crypto interface) · Red Hat Enterprise Linux (including AUS, EUS, TUS, and Update Services for SAP Solutions) KEV PoC ×5mass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.