Hackers are exploiting a vulnerability in unpatched Atlassian servers to deploy a Linux variant of Cerber ransomware.

Specifically, the attacks exploit the vulnerability CVE-2023-22518 (CVSS score: 9.1), which affects Atlassian Confluence Data Center and Server and allows an unauthorized user to reset Confluence and create an account administrator Attackers can then take control of the vulnerable systems.
According to security firm Cado, cybercriminals are abusing the newly created administrator account to install the Effluence web shell plugin and execute commands on the host computer.
See also: Change Healthcare: Ransomware attack cost $872 million
“The attacker uses this web shell to download and execute the main Cerber ransomware payload,” said Nate Bill, a Cado executive.
“In a default installation, the Confluence application runs as the “confluence” user, a low-privilege user. Therefore, the data that the ransomware can encrypt is limited to files owned by the confluence user.“.
This is not the first time we've heard that Atlassian's CVE-2023-22518 vulnerability is being used to deploy Cerber ransomware.
Cerber is written in C++ and can act as a loader for additional malware, retrieving it from a command-and-control (C2) server.
The encryptor encrypts all contents and adds the .L0CK3D to encrypted files. It also displays a ransom note in each directory.
See also: Jackson County networks restored after ransomware

“Cerber is a relatively sophisticated, albeit old, ransomware payload,” Bill said. “While its use of the Confluence vulnerability allows it to compromise a large number of systems , the data it is able to encrypt is often limited to confluence data. On well-configured systems, backups are created for this data.” The researcher explained that this limits the effectiveness of the ransomware, as there is much less incentive to pay.
Ransomware protection
Protecting against ransomware attacks requires preventative measures. One of these is informing and educating users to recognize and avoid suspicious emails or links that may contain malware.
It is also important to keep the operating system and all installed programs up to date, as updates often include security fixes that can protect against new forms of ransomware (e.g. new version of Cerber).
See also: Nexperia: Ransomware attack and data breach
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Backing up your data is essential to protect your most important data. Using reliable antivirus software is another important practice for protecting against ransomware attacks.
Finally, using tools to restrict user rights and implementing the principle of least privilege can help protect against attacks by limiting the malware's ability to extend its impact on the system.
Source: thehackernews.com
