Threat Advisory

Godzilla Backdoor Targeting Atlassian Confluence Servers with Fileless Attacks

Threat: Vulnerability/Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical remote code execution (RCE) vulnerability, CVE-2023-22527, has been identified in older versions of Atlassian Confluence Data Center and Server. Exploiting this flaw, attackers can remotely execute malicious code on vulnerable systems. A fileless, in-memory backdoor known as the Godzilla webshell is being deployed in conjunction with this vulnerability, allowing threat actors to bypass traditional disk-based detection methods. This attack has been linked to various malicious activities, including crypto-mining and potentially broader operations.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical remote code execution (RCE) vulnerability, CVE-2023-22527, has been identified in older versions of Atlassian Confluence Data Center and Server. Exploiting this flaw, attackers can remotely execute malicious code on vulnerable systems. A fileless, in-memory backdoor known as the Godzilla webshell is being deployed in conjunction with this vulnerability, allowing threat actors to bypass traditional disk-based detection methods. This attack has been linked to various malicious activities, including crypto-mining and potentially broader operations.[emaillocker id="1283"]

 

The attack begins by exploiting a template injection vulnerability in Confluence, allowing unauthorized execution of OGNL objects. A malicious payload is then introduced, loading the Godzilla webshell into memory. Godzilla uses AES encryption to secure communications and employs dynamic class loading to inject a custom valve into the Tomcat server, enabling persistent unauthorized access. The payload includes Base64-encoded anonymous classes, which are decoded and executed in-memory using Java Reflection, making detection by traditional anti-virus solutions particularly difficult. This fileless nature further complicates detection, as the malware resides solely in memory without leaving traces on disk.

 

Organizations using Atlassian Confluence should prioritize patching their systems to mitigate the risk of this vulnerability being exploited. Additionally, advanced security solutions that provide enhanced threat detection beyond signature-based methods are recommended to defend against fileless malware attacks like Godzilla. By staying proactive with security updates and leveraging modern defense mechanisms, organizations can minimize the risk of compromise from this critical vulnerability.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access  T1190 Exploit Public-Facing Application
 Execution T1059 Command and Scripting Interpreter
Persistence  T1505 Server Software Component
 Defense Evasion  T1027 Obfuscated Files or Information
T1620 Reflective Code Loading
T1055 Process Injection
 T1140 Deobfuscate/Decode Files or Information
Command and Control  T1573 Encrypted Channel
Exfiltration T1048 Exfiltration Over Alternative Protocol

RECOMMENDATION:

  • We strongly recommend you update Confluence Data Center and Server to version 8.5.5 (LTS) and Confluence Data Center to version 8.7.2 (Data Center Only).

REFERENCES:

The following reports contain further technical details:
https://www.trendmicro.com/en_us/research/24/h/godzilla-fileless-backdoors.html

[/emaillocker]
crossmenu