Hackers are exploiting a critical security vulnerabilityaffecting Atlassian Confluence Data Center and Confluence Server to carry out crypto-mining attacks. It is worth noting that this vulnerability has now been fixed, but unpatched systems remain vulnerable.

“Attackers are using methods such as deploying shell scripts and XMRig miners, targeting SSH endpoints, disrupting competing crypto mining processes, and maintaining persistence via cron jobs,” said Trend Micro researcher Abdelrahman Esmail.
The vulnerability is tracked as CVE-2023-22527 and affects older versions of Atlassian Confluence Data Center and Confluence Server. Unauthorized attackers could exploit it to perform remote code execution. Atlassian patched this vulnerability in mid-January 2024.
See also: Dell BIOS vulnerability allows arbitrary code execution
Trend Micro observed multiple exploit attempts from mid-June to late July 2024. Attackers used it to distribute the XMRig miner to unpatched devices. At least three different hacking groups appear to have exploited the Atlassian Confluence vulnerability.
Researchers observed that the XMRig miner is launched via an ELF file payload (using specially crafted requests). First, a shell script is used that terminates competing cryptojacking (e.g. Kinsing), deletes cron jobs, uninstalls cloud security tools from Alibaba and Tencent , and collects system information. Finally, it sets up a new cron job that checks for command-and-control (C2) server connectivity every five minutes and launches the miner.
See also: Hitachi vulnerabilities affect power SCADA systems
Researcher Esmail emphasized that the CVE-2023-22527 vulnerability poses a significant risk to organizations worldwide, given its widespread exploitation.
“To minimize the risks and threats associated with this vulnerability, administrators should update their versions of Confluence Data Center and Confluence Server to the latest available versions as soon as possible,” the researcher suggests.

Organizations using affected versions of Atlassian Confluence are urged to immediately apply available security updates and review their security measures to protect themselves from potential attacks. In addition, it is crucial to raise awareness and educate users, as well as monitor their systems for any unusual activity.
See also: Fortra fixes critical vulnerability in FileCatalyst Workflow
Additionally, companies must have detection and response systems to resolve any security issues and promote continuous improvement of security .
Finally, collaborating with external security can help develop and implement effective prevention and protection measures. Only through coordinated efforts and sophisticated security systems can we protect ourselves from attacks and ensure the security of our systems.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
