ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 3 sources: “Linux kernel flaw 'Copy Fail' (CVE-2026-31431): ABB Edgenius advisory and Feral Wolf GenieLocker ransomware attacks” — merged summary and timeline →

Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems

mediumRansomware exploited in the wildimportance 58CVE-2023-22515CVE-2026-31431
AI summary · glm-5.3-flash

BI.ZONE links Feral Wolf ransomware attacks on Russian firms to Confluence CVE-2023-22515 exploitation and exposed 1C clusters, deploying GenieLocker.

BI.ZONE documented Feral Wolf ransomware intrusions against Russian retail, construction, manufacturing and IT organizations from May through August 2026. Attackers exploited CVE-2023-22515 on internet-facing Atlassian Confluence servers, abused unauthenticated 1C:Enterprise cluster management and debug modes to execute OS commands, and escalated from a restricted Docker container to the host via a weak-password PostgreSQL service. They used newly documented MQTTDoor and MatrixDoor backdoors, an RDP-tunneling proxy, credential harvesting from memory dumps, and the GenieLocker encryptor, blending C2 into legitimate protocols to evade detection.

  • Exploited CVE-2023-22515 to create an admin account on a Dockerized Confluence server
  • Weak PostgreSQL password enabled container-to-host escape and further network discovery
  • Unauthenticated 1C:Enterprise cluster management allowed arbitrary OS command execution
  • MQTTDoor and MatrixDoor backdoors hide C2 in legitimate MQTT and Matrix traffic
  • PowerShell scripts used to remove forensic traces; IoCs and GenieLocker hashes published

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-22515
Unauthenticated Broken Access Control in Atlassian Confluence Data Center/Server

Atlassian Confluence Data Center and Server contain a broken access control flaw (CWE-20) in publicly accessible instances that allows unauthenticated remote attackers to create unauthorized Confluence administrator accounts and gain access to the instance; the associated public PoC is titled 'Atlassian Confluence Unauthenticated Remote Code Execution'. The flaw is triggered over the network (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N) against any self-managed Confluence instance reachable from the internet, with no privileges or user interaction required. Attackers who exploit it gain administrator-level control of the Confluence instance, and the public PoC demonstrates this extends to unauthenticated code execution. Only self-managed Confluence Data Center and Server deployments are affected; Atlassian Cloud sites hosted on atlassian.net domains are not vulnerable. Exploitation is confirmed in the wild: CISA added it to the KEV on 2023-10-05 with known ransomware use, EPSS is 99.2%, Atlassian reported a handful of customers were already exploited, and Microsoft warned of nation-state (China-linked) abuse.

Do: Patch all internet-facing Confluence Data Center and Server instances to a fixed release per Atlassian's advisory (specific fixed versions are not listed in this data), or restrict public access/discontinue use per CISA's required action. Audit every affected instance for evidence of compromise, especially unauthorized administrator accounts created through this flaw, and report positive findings to CISA. Treat this as urgent given active exploitation by both nation-state actors and ransomware groups.

9.899% KEV ransomware PoC
  • Atlassian Confluence Data Center
  • Atlassian Confluence Server
large≈ tens of thousands of internet-exposed Confluence Data Center/Server instances (order of ~30,000-50,000)
CVE-2026-31431
Local Privilege Escalation (Copy Fail) in Linux Kernel algif_aead Interface

CVE-2026-31431 ('Copy Fail') is an incorrect resource transfer between spheres (CWE-669/CWE-1288) in the Linux kernel's algif_aead implementation of the AF_ALG userspace crypto interface, introduced roughly nine years ago (around 2017, per public reporting) when commit 72548b093ee3 switched AEAD operations to in-place handling even though the source and destination buffers come from different mappings. A local, unprivileged user can trigger the flaw by performing AEAD operations through the AF_ALG socket interface, causing the kernel to mishandle the copy of ciphertext and associated data. Successful exploitation provides a reliable local privilege escalation to root (C:H/I:H/A:H per the CVSS vector). Nearly every major Linux distribution and enterprise platform is exposed, including the kernel itself, Red Hat Enterprise Linux (including AUS, EUS, TUS and Update Services for SAP Solutions), OpenShift Container Platform, Amazon Linux, Ubuntu, Debian, openSUSE Leap, SUSE CaaS Platform, NixOS, and Linux-based products from Arista and Siemens. The flaw has public proof-of-concept code, a 99.9% EPSS score, and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-01, indicating exploitation in the wild (ransomware use is unknown).

Do: Patch by installing the kernel update for CVE-2026-31431 through your distribution's security channel (Red Hat Enterprise Linux including AUS/EUS/TUS/SAP channels, OpenShift, Amazon Linux, Ubuntu, Debian, openSUSE Leap, SUSE CaaS Platform, NixOS, and Arista/Siemens firmware/software as applicable) and reboot into the patched kernel; the data provides no fixed version numbers, so defer to vendor advisories. Because the flaw is in CISA's KEV catalog (added 2026-05-01) with a 99.9% EPSS score, prioritize internet-reachable and multi-user systems first and follow BOD 22-01 guidance for cloud services. Check running kernel versions ('uname -r') and distribution advisory status to confirm you are on a fixed build.

7.8100% KEV PoC ×5
  • Linux kernel (algif_aead / AF_ALG crypto interface)
  • Red Hat Enterprise Linux (including AUS, EUS, TUS, and Update Services for SAP Solutions)
  • Red Hat OpenShift Container Platform
  • +8 more
masshundreds of millions to billions of installations (servers, cloud instances, desktops, and Android/embedded devices running affected kernel generations)

Indicators of compromiseAll →

TypeIndicatorContext
domainelement.tw]com MQTT broker used by the MQTTDoor backdoor. Domain meet.element[.]tw Matrix homeserver used by the MatrixDoor backdoor. URL hx
domaingithub.comrix homeserver used by the MatrixDoor backdoor. URL hxxps://github[.]com/itm4n/PrintSpoofer/releases/download/v1.0/PrintSpoofer64.
domaingithubusercontent.comoad location observed in attacker commands. URL hxxps://raw.githubusercontent[.]com/evilsocket/nyx/refs/heads/main/nyx.ps1 Script-download lo
domainhivemq.comQL server contacted by the 1C server process. Domain broker.hivemq[.]com MQTT broker used by the MQTTDoor backdoor. Domain meet.el
sha256023a8a4e54dd9264a7d0cca3fd08cae15c661c91bb477dfc08a5c0f9939fb5cb70e3ccc1123fc2fac9cf43862369f335 GenieLocker sample SHA-256 023a8a4e54dd9264a7d0cca3fd08cae15c661c91bb477dfc08a5c0f9939fb5cb GenieLocker sample SHA-256 588f817d9047f093ee8b68d1d50354a2
sha2561e2e08a36b6126f2363c24b5fe7a6dbd755c35b1cb6f15cdea13fc93274019f354b2935703422d44f02e403d2e78 gs-dbus GSocket sample SHA-256 1e2e08a36b6126f2363c24b5fe7a6dbd755c35b1cb6f15cdea13fc93274019f3 exploit_cve_2026_31431.py SHA-256 e82ecbe3823046a27d8c39cc0
sha2562539170c4c1ffeeb17e87917687b5f86104cc88de9478696cee6e0ecaddfc9bb1d937b721fad95c63374f7dd0570d1b1e9d96c41 memfix.zip SHA-256 2539170c4c1ffeeb17e87917687b5f86104cc88de9478696cee6e0ecaddfc9bb gs-dbus GSocket sample SHA-256 cb5f62bf7b591e69bd38e6bf8e40
sha256487886e5058294b7d965421f1d937b721fad95c63374f7dd0570d1b1e9d96c41pt-download location observed in attacker commands. SHA-256 487886e5058294b7d965421f1d937b721fad95c63374f7dd0570d1b1e9d96c41 memfix.zip SHA-256 2539170c4c1ffeeb17e87917687b5f86104cc88d
sha256588f817d9047f093ee8b68d1d50354a2f5cd5d01451512bdb75d726e61e419fa5c661c91bb477dfc08a5c0f9939fb5cb GenieLocker sample SHA-256 588f817d9047f093ee8b68d1d50354a2f5cd5d01451512bdb75d726e61e419fa MQTTDoor SHA-256 c6a0476571cf67255001201be70f6fdfc3ac945515
sha256b4c7e52bf47f8770683b13c6bdaee80924511673b94a6eb46157dffee8e92d05e70f6fdfc3ac945515c1c8b327a9a92a4e89991d MatrixDoor SHA-256 b4c7e52bf47f8770683b13c6bdaee80924511673b94a6eb46157dffee8e92d05 RDPSocksProxy Note: IP addresses and domains are intentiona
sha256c6a0476571cf67255001201be70f6fdfc3ac945515c1c8b327a9a92a4e89991dd1d50354a2f5cd5d01451512bdb75d726e61e419fa MQTTDoor SHA-256 c6a0476571cf67255001201be70f6fdfc3ac945515c1c8b327a9a92a4e89991d MatrixDoor SHA-256 b4c7e52bf47f8770683b13c6bdaee80924511673
sha256cb5f62bf7b591e69bd38e6bf8e40e8d307d154b2935703422d44f02e403d2e78c88de9478696cee6e0ecaddfc9bb gs-dbus GSocket sample SHA-256 cb5f62bf7b591e69bd38e6bf8e40e8d307d154b2935703422d44f02e403d2e78 gs-dbus GSocket sample SHA-256 1e2e08a36b6126f2363c24b5fe7a
sha256ccfc37014ce6183bb9268e15e8569fc870e3ccc1123fc2fac9cf43862369f335c39cc0a4acb498f415549946c9ff0e241838b34ed5a21 fscan SHA-256 ccfc37014ce6183bb9268e15e8569fc870e3ccc1123fc2fac9cf43862369f335 GenieLocker sample SHA-256 023a8a4e54dd9264a7d0cca3fd08cae1
sha256e82ecbe3823046a27d8c39cc0a4acb498f415549946c9ff0e241838b34ed5a211cb6f15cdea13fc93274019f3 exploit_cve_2026_31431.py SHA-256 e82ecbe3823046a27d8c39cc0a4acb498f415549946c9ff0e241838b34ed5a21 fscan SHA-256 ccfc37014ce6183bb9268e15e8569fc870e3ccc1123fc
urlhttps://github[.]tw Matrix homeserver used by the MatrixDoor backdoor. URL hxxps://github[.]com/itm4n/PrintSpoofer/releases/download/v1.0/PrintSpoofer
urlhttps://raw.githubusercontent[e Tool-download location observed in attacker commands. URL hxxps://raw.githubusercontent[.]com/evilsocket/nyx/refs/heads/main/nyx.ps1 Script-download
Full article844 words · extracted from cybersecuritynews.com · click to collapse

Feral Wolf is using exposed business software and weak server settings to reach corporate networks, then locking files with ransomware. The campaign shows how one overlooked internet-facing system can become the starting point for a much larger incident.

The group targeted Russian organizations in retail, construction, manufacturing, and information technology from May through August 2026. Its operators combined exploitation, stolen or weak credentials, remote access, and custom backdoors before deploying GenieLocker to encrypt data.

Analysts at BI.ZONE identified the activity while investigating the intrusions, documenting paths through vulnerable Atlassian Confluence installations, contractor environments, and poorly protected 1C:Enterprise clusters. The cases underline why external services need the same attention as core business systems.

BI.ZONE said in a report shared with Cyber Security News (CSN) that the operators also used legitimate-looking communication channels to remain active longer. That choice can make hostile traffic blend in with routine network activity and delay a defender’s response.

Feral Wolf Ransomware

One intrusion began with a publicly accessible Confluence server running inside a Docker container behind a proxy. Feral Wolf exploited CVE-2023-22515, created an account, and placed it in the Confluence administrator group.

Earlier coverage of the actively exploited Atlassian zero-day flaw illustrates why exposed collaboration platforms require rapid patching and regular account reviews.

From the container, the attackers established a foothold, ran network discovery, and found a PostgreSQL service using a weak password.

Access to that database gave them a route from the restricted container to the underlying host, where they ran commands and continued scanning the internal network.

The operation also abused insecure 1C:Enterprise server clusters exposed online. Where cluster administration was not protected, the attackers could connect to the management service and perform administrative actions without first proving their identity.

They then used specially prepared 1C database content or external processing files to make the server run operating-system commands.

A separate incident involved a cluster manager operating in debug mode. Its extra functions could be misused to launch external applications, leaving temporary command files as a potential warning sign.

These paths resemble the risks in Confluence server ransomware intrusions, where an initial application compromise rapidly becomes broader network access.

Backdoors, credential theft, and defense

After gaining access, Feral Wolf used newly documented backdoors that communicate through MQTT and Matrix, alongside a proxy utility that tunnels traffic through an existing Remote Desktop Protocol session.

By relying on widely used protocols rather than an unusual connection method, the group made command-and-control traffic harder to separate from normal activity. The attackers also collected memory from Windows systems with legitimate utilities and examined it for credentials.

In another case, they attempted to erase evidence using a PowerShell script designed to remove forensic traces. These actions can help an intruder move between systems while limiting the clues available to incident responders.

Organizations should patch Confluence promptly, remove unnecessary public access, and review administrator accounts and proxy logs.

Teams running 1C should require strong cluster administrator authentication, keep management services off the public internet, and disable debug capabilities unless they are essential.

Segmenting database and container-host networks also reduces the damage when one application is breached. Security teams should watch for unexpected administrative changes, suspicious outbound traffic over otherwise permitted protocols, unusual Remote Desktop activity, and creation of memory dumps.

Monitoring events across servers, containers, identity systems, and network boundaries can surface the linked actions earlier. The Docker host compromise risk is especially relevant when a compromised workload can reach services outside its intended isolation.

The investigation is a reminder that ransomware is rarely a single-event failure. Feral Wolf paired known flaws and configuration gaps with credential access, covert communications, and data encryption.

Closing exposed entry points and detecting the movement that follows are equally important to stopping the attack before its final stage.

That discipline matters because routine checks can connect internet exposure, configuration changes, administrator behavior, anomalous remote activity, and abnormal internal access before encryption begins.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IP address45.151.45[.]31Source IP associated with the Confluence intrusion.
IP address46.166.79[.]31External PostgreSQL server contacted by the 1C server process.
Domainbroker.hivemq[.]comMQTT broker used by the MQTTDoor backdoor.
Domainmeet.element[.]twMatrix homeserver used by the MatrixDoor backdoor.
URLhxxps://github[.]com/itm4n/PrintSpoofer/releases/download/v1.0/PrintSpoofer64.exeTool-download location observed in attacker commands.
URLhxxps://raw.githubusercontent[.]com/evilsocket/nyx/refs/heads/main/nyx.ps1Script-download location observed in attacker commands.
SHA-256487886e5058294b7d965421f1d937b721fad95c63374f7dd0570d1b1e9d96c41memfix.zip
SHA-2562539170c4c1ffeeb17e87917687b5f86104cc88de9478696cee6e0ecaddfc9bbgs-dbus GSocket sample
SHA-256cb5f62bf7b591e69bd38e6bf8e40e8d307d154b2935703422d44f02e403d2e78gs-dbus GSocket sample
SHA-2561e2e08a36b6126f2363c24b5fe7a6dbd755c35b1cb6f15cdea13fc93274019f3exploit_cve_2026_31431.py
SHA-256e82ecbe3823046a27d8c39cc0a4acb498f415549946c9ff0e241838b34ed5a21fscan
SHA-256ccfc37014ce6183bb9268e15e8569fc870e3ccc1123fc2fac9cf43862369f335GenieLocker sample
SHA-256023a8a4e54dd9264a7d0cca3fd08cae15c661c91bb477dfc08a5c0f9939fb5cbGenieLocker sample
SHA-256588f817d9047f093ee8b68d1d50354a2f5cd5d01451512bdb75d726e61e419faMQTTDoor
SHA-256c6a0476571cf67255001201be70f6fdfc3ac945515c1c8b327a9a92a4e89991dMatrixDoor
SHA-256b4c7e52bf47f8770683b13c6bdaee80924511673b94a6eb46157dffee8e92d05RDPSocksProxy

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/feral-wolf-ransomware/