EXECUTIVE SUMMARY
A critical vulnerability, CVE-2023-22527, is actively being exploited in cryptojacking campaigns, turning affected environments into cryptomining networks. Attackers exploit this vulnerability by deploying shell scripts and XMRig miners, targeting SSH endpoints, terminating competing cryptomining processes, and maintaining persistence through cron jobs. Organizations are urged to update their Confluence instances to the versions and adopt security best practices to protect their systems from these attacks.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A critical vulnerability, CVE-2023-22527, is actively being exploited in cryptojacking campaigns, turning affected environments into cryptomining networks. Attackers exploit this vulnerability by deploying shell scripts and XMRig miners, targeting SSH endpoints, terminating competing cryptomining processes, and maintaining persistence through cron jobs. Organizations are urged to update their Confluence instances to the versions and adopt security best practices to protect their systems from these attacks.[emaillocker id="1283"]
The CVE-2023-22527 vulnerability allows unauthenticated attackers to exploit a template injection flaw in older versions of Confluence Data Center and Server, enabling remote code execution (RCE). Attackers have weaponized this vulnerability for cryptomining activities, notably deploying XMRig miners. The first threat actor utilized an ELF file payload to execute miner activities, while the second threat actor employed a shell script to execute cryptomining via SSH on accessible endpoints. The attack script is designed to terminate competing cryptomining processes, remove existing cron jobs, and establish new cron jobs that connect to command-and-control servers. Additionally, the script disables cloud security services and uses SSH to spread cryptomining activities across the local network. The attacker ensures persistence by creating multiple cron jobs and then clears logs and bash history to remove traces of the attack.
The ongoing exploitation of CVE-2023-22527 poses a serious security threat to organizations. To mitigate these risks, it is imperative to promptly update their Confluence instances to the latest available versions. Additionally, organizations should adopt best practices such as regular patch management, network segmentation, security audits, and maintaining an effective incident response plan. Implementing advanced security solutions like intrusion prevention systems and conducting regular vulnerability scans can also help strengthen defenses against these exploit attempts.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| T1053 | Scheduled Task/Job | |
| Defense Evasion | T1562 | Impair Defenses |
| T1070 | Indicator Removal | |
| Collection | T1005 | Data from Local System |
| Command and Control | T1105 | Ingress Tool Transfer |
| Impact | T1496 | Resource Hijacking |
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://www.darkreading.com/threat-intelligence/attackers-exploit-critical-atlassian-confluence-flaw-for-cryptojacking