An advanced ransomware attack exploits a critical vulnerability in Atlassian Confluence (CVE-2023-22527, CVSS 10.0), threatening the security of corporate networks. The vulnerability allows attackers to deploy the LockBit Black ransomware within just two hours of the initial breach, causing serious consequences for affected businesses.
See also: Zservers Sanctioned for “Providing Assistance” to LockBit Ransomware Group

The attackers carried out a complex, multi-layered attack, which included credential theft, RDP lateral movement, and automated ransomware propagation. To carry out the attack, they leveraged legitimate tools, such as PDQ Deploy, enhancing the effectiveness and concealment of their actions.
The attack began by exploiting CVE-2023-22527, a critical flaw in the server-side pattern injection mechanism. This flaw allows remote code execution (RCE) without requiring authentication, making it particularly dangerous.
Attackers exploited the vulnerability by injecting malicious OGNL (Object-Graph Navigation Language) expressions via HTTP POST requests to the /template/aui/text-inline.vm endpoint . This allowed them to execute commands with the privileges of the NETWORK SERVICE account.
See also: Ransomware gangs use LockBit's fame to pressure victims
According to cybersecurity analysts at The DFIR Report, the initial identification commands, such as net user and whoami, were executed via a Python script. This is confirmed by the presence of the user-agent python-requests/2.25 in the server logs.

After securing a Meterpreter session via a malicious HTA file, the attackers used AnyDesk to gain permanent access to the system. They disabled defenses by entering the word “virus” in the Windows Start menu, thereby disabling Defender, while also deleting log files via PowerShell.
webtutil el | ForEach-Object { wevtutil cl “$_” }
After the removal, the hackers used tools like Mimikatz and Rclone to erase traces:
C:\temp\mimikatz\x64\mimikatz.exe
C:\temp\rclone\rclone.exe
See also: Crypt Ghouls targets Russian businesses with LockBit 3.0 and Babuk ransomware
Confluence Server has recently been identified with a critical vulnerability that poses a significant security risk to organizations using the platform, as it allows LockBit ransomware attacks. This vulnerability allows attackers to exploit a weakness in the system, potentially leading to unauthorized access to sensitive data or disruption of operations. Atlassian, the company behind Confluence, has advised all users to immediately update to the latest patch to mitigate this risk. Additionally, implementing best practices, such as restricting access to the Confluence server and monitoring for unusual activity, can help reduce potential exposure. Regular system updates and proactive security measures are essential to protect against such threats.
Source: cybersecuritynews
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
