HomeSecurityConfluence Server Vulnerability Allows LockBit Ransomware Attacks

Confluence Server Vulnerability Allows LockBit Ransomware Attacks

An advanced ransomware attack exploits a critical vulnerability in Atlassian Confluence (CVE-2023-22527, CVSS 10.0), threatening the security of corporate networks. The vulnerability allows attackers to deploy the LockBit Black ransomware within just two hours of the initial breach, causing serious consequences for affected businesses.

See also: Zservers Sanctioned for “Providing Assistance” to LockBit Ransomware Group

LockBit Ransomware vulnerability

The attackers carried out a complex, multi-layered attack, which included credential theft, RDP lateral movement, and automated ransomware propagation. To carry out the attack, they leveraged legitimate tools, such as PDQ Deploy, enhancing the effectiveness and concealment of their actions.

The attack began by exploiting CVE-2023-22527, a critical flaw in the server-side pattern injection mechanism. This flaw allows remote code execution (RCE) without requiring authentication, making it particularly dangerous.

Attackers exploited the vulnerability by injecting malicious OGNL (Object-Graph Navigation Language) expressions via HTTP POST requests to the /template/aui/text-inline.vm endpoint . This allowed them to execute commands with the privileges of the NETWORK SERVICE account.

See also: Ransomware gangs use LockBit's fame to pressure victims

According to cybersecurity analysts at The DFIR Report, the initial identification commands, such as net user and whoami, were executed via a Python script. This is confirmed by the presence of the user-agent python-requests/2.25 in the server logs.

Confluence Server Vulnerability Allows LockBit Ransomware Attacks
Confluence Server Vulnerability Allows LockBit Ransomware Attacks

After securing a Meterpreter session via a malicious HTA file, the attackers used AnyDesk to gain permanent access to the system. They disabled defenses by entering the word “virus” in the Windows Start menu, thereby disabling Defender, while also deleting log files via PowerShell.

webtutil el | ForEach-Object { wevtutil cl “$_” }

After the removal, the hackers used tools like Mimikatz and Rclone to erase traces:

C:\temp\mimikatz\x64\mimikatz.exe
C:\temp\rclone\rclone.exe

See also: Crypt Ghouls targets Russian businesses with LockBit 3.0 and Babuk ransomware

Confluence Server has recently been identified with a critical vulnerability that poses a significant security risk to organizations using the platform, as it allows LockBit ransomware attacks. This vulnerability allows attackers to exploit a weakness in the system, potentially leading to unauthorized access to sensitive data or disruption of operations. Atlassian, the company behind Confluence, has advised all users to immediately update to the latest patch to mitigate this risk. Additionally, implementing best practices, such as restricting access to the Confluence server and monitoring for unusual activity, can help reduce potential exposure. Regular system updates and proactive security measures are essential to protect against such threats.

Source: cybersecuritynews

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS