Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware
Feral Wolf exploited Atlassian Confluence and 1C:Enterprise flaws to deploy GenieLocker ransomware across Russian retail, construction, manufacturing and IT firms.
BI.ZONE DFIR tracked Feral Wolf intrusions at Russian retail, construction, manufacturing, and IT organizations from May through August 2026. The actor exploited CVE-2023-22515 on internet-facing Confluence instances, deployed GSocket and Rust-based MQTTDoor/MatrixDoor backdoors using MQTT and Matrix C2, and used PwnKit (CVE-2021-4034) and Copy Fail (CVE-2026-31431) for privilege escalation and container-to-host escape. The group abused exposed 1C:Enterprise cluster managers and weak PostgreSQL credentials to move laterally before deploying GenieLocker ransomware.