Huntress confirmed active exploitation of CVE-2023-22518, an improper authorization vulnerability in Atlassian Confluence Data Center and Server, beginning November 3, 2023 — just days after Atlassian released patches. Attackers exploited the unauthenticated /json/setup-restore.action endpoint to inject a malicious admin user, then deployed Cerber ransomware (C3RB3R) via encoded PowerShell commands that downloaded and executed a hex-encoded PE payload. The attack chain involved creating a new admin account, installing a web shell plugin, and dropping ransomware that appends 'L0CK3D' to encrypted files. Mitigation guidance includes immediate patching, attack surface minimization, placing Confluence behind VPNs, and maintaining defense-in-depth postures to detect post-exploitation activity.

5m read timeFrom huntress.com
Post cover image
Table of contents
Exploitation MechanicsAttack SurfaceWhat Can You Do?