Threat Advisory

Atlassian Vulnerabilities Exploited in New Cryptojacking Campaign on Cloud Environments

Threat: Vulnerability/Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical vulnerability, CVE-2023-22527, is actively being exploited in cryptojacking campaigns, turning affected environments into cryptomining networks. Attackers exploit this vulnerability by deploying shell scripts and XMRig miners, targeting SSH endpoints, terminating competing cryptomining processes, and maintaining persistence through cron jobs. Organizations are urged to update their Confluence instances to the versions and adopt security best practices to protect their systems from these attacks.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical vulnerability, CVE-2023-22527, is actively being exploited in cryptojacking campaigns, turning affected environments into cryptomining networks. Attackers exploit this vulnerability by deploying shell scripts and XMRig miners, targeting SSH endpoints, terminating competing cryptomining processes, and maintaining persistence through cron jobs. Organizations are urged to update their Confluence instances to the versions and adopt security best practices to protect their systems from these attacks.[emaillocker id="1283"]

 

The CVE-2023-22527 vulnerability allows unauthenticated attackers to exploit a template injection flaw in older versions of Confluence Data Center and Server, enabling remote code execution (RCE). Attackers have weaponized this vulnerability for cryptomining activities, notably deploying XMRig miners. The first threat actor utilized an ELF file payload to execute miner activities, while the second threat actor employed a shell script to execute cryptomining via SSH on accessible endpoints. The attack script is designed to terminate competing cryptomining processes, remove existing cron jobs, and establish new cron jobs that connect to command-and-control servers. Additionally, the script disables cloud security services and uses SSH to spread cryptomining activities across the local network. The attacker ensures persistence by creating multiple cron jobs and then clears logs and bash history to remove traces of the attack.

The ongoing exploitation of CVE-2023-22527 poses a serious security threat to organizations. To mitigate these risks, it is imperative to promptly update their Confluence instances to the latest available versions. Additionally, organizations should adopt best practices such as regular patch management, network segmentation, security audits, and maintaining an effective incident response plan. Implementing advanced security solutions like intrusion prevention systems and conducting regular vulnerability scans can also help strengthen defenses against these exploit attempts.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access  T1190 Exploit Public-Facing Application
Execution T1059 Command and Scripting Interpreter
T1053 Scheduled Task/Job
Defense Evasion T1562 Impair Defenses
T1070 Indicator Removal
Collection  T1005 Data from Local System
Command and Control T1105 Ingress Tool Transfer
Impact T1496 Resource Hijacking

RECOMMENDATION:

  • We strongly recommend you update Confluence Data Center and Server to version 8.5.5 (LTS) and Confluence Data Center to version 8.7.2 (Data Center Only).

REFERENCES:

The following reports contain further technical details:
https://www.darkreading.com/threat-intelligence/attackers-exploit-critical-atlassian-confluence-flaw-for-cryptojacking

[/emaillocker]
crossmenu