Confluence and GitLab servers targeted by new ransomware strain
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-22205 | Unauthenticated RCE in GitLab CE/EE via ExifTool Image Parsing (CVE-2021-22205) GitLab CE/EE versions from 11.9 onward fail to properly validate image files before passing them to the bundled ExifTool file parser, enabling command/code injection (CWE-94). A remote, unauthenticated attacker triggers it by getting the server to parse a specially crafted image (e.g., through file-upload features), with no credentials or user interaction required. Successful exploitation yields arbitrary command execution on the GitLab server, exposing source code, credentials, CI/CD data, and the wider network (CVSS 10.0, scope-changed). All self-managed GitLab Community and Enterprise Edition deployments on affected versions are exposed. The flaw is actively exploited in the wild: it is on CISA's KEV with known ransomware use, public PoCs exist, and 2021 campaigns used it for ransomware, cryptojacking, and access brokering against GitLab servers. Do: Upgrade immediately to the patched releases - 13.10.3 or later, or the corresponding 13.9.6/13.8.6/13.7.9 backports - per vendor instructions, as required for KEV entries. Until patched, restrict network access to internet-facing GitLab instances and verify the bundled ExifTool is current. Hunt for signs of compromise (suspicious processes or cron jobs, cryptominers, webshells, new SSH keys, unexpected outbound connections), given documented ransomware and cryptojacking abuse. | 10.0 | 100% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed self-managed GitLab instances (order of ~50,000+ servers in public scans) | |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability CVE-2021-26084 is an OGNL injection vulnerability (CWE-917) in Atlassian Confluence Server and Data Center that may allow an unauthenticated attacker to execute arbitrary code. Any organization running Confluence Server or Data Center is potentially affected. It is significant because it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, and EPSS assigns a 100.0% probability of exploitation within 30 days (100th percentile). Do: Apply updates to Confluence Server and Data Center per Atlassian's instructions, which is the required action in the CISA KEV listing. Prioritize remediation given confirmed in-the-wild exploitation and known ransomware use. | 9.8 | 100% | KEV ransomware PoC |
| — |
Full article380 words · extracted from therecord.media · click to collapse
Over the past few days, a ransomware group has leveraged exploits for recently disclosed vulnerabilities to gain access to unpatched Confluence and GitLab servers, encrypt their files, and then ask server owners for a ransom payment to recover their data. The attacks, spotted by security researcher MalwareHunterTeam and Tencent Security, have hit hundreds of servers so far, with both Windows and Linux systems being encrypted. Impacted servers can be recognized by the addition of a ".locked" file extension at the end of each encrypted file. Once a Confluence or GitHub server is hit, it starts returning 404 errors, preventing users from logging into their accounts. Administrators who investigate will eventually stumble over a file named __$$RECOVERY_README$$__.html, which contains the attackers' ransom demand. The ransom note—pictured above—is identical to the one used by Cerber, a now-defunct ransomware operation that was active between 2016 and 2019. However, analysis of the code suggests this is a completely different ransomware strain, one that merely tries to hijack another gang's brand in an attempt to scare victims into paying to regain access to their files. According to Tencent, the group has been exploiting CVE-2021-26084 and CVE-2021-22205 to gain access to Confluence and GitLab servers, respectively. Both vulnerabilities are remote code execution bugs that can grant attackers full control over unpatched systems; hence, the attackers' ability to run ransomware and encrypt files with ease. Both issues have been disclosed earlier this year, have patches available, and have already been exploited in the wild by multiple threat actors since September and November, respectively, meaning that companies have no excuse to still be running outdated systems at this point. For example, Confluence servers have also been targeted by the Atom Silo ransomware since October, according to a Sophos report. Per Tencent, the vast majority of (new) Cerber victims are currently located in China, Germany, and the US. Attackers are asking for 0.04 bitcoin (~$2,000) to provide a decrypter to victims, a sum that will double after five days.
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/confluence-and-gitlab-servers-targeted-by-new-ransomware-strain