EXECUTIVE SUMMARY
A critical remote code execution (RCE) vulnerability, CVE-2023-22527, has been identified in older versions of Atlassian Confluence Data Center and Server. Exploiting this flaw, attackers can remotely execute malicious code on vulnerable systems. A fileless, in-memory backdoor known as the Godzilla webshell is being deployed in conjunction with this vulnerability, allowing threat actors to bypass traditional disk-based detection methods. This attack has been linked to various malicious activities, including crypto-mining and potentially broader operations.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A critical remote code execution (RCE) vulnerability, CVE-2023-22527, has been identified in older versions of Atlassian Confluence Data Center and Server. Exploiting this flaw, attackers can remotely execute malicious code on vulnerable systems. A fileless, in-memory backdoor known as the Godzilla webshell is being deployed in conjunction with this vulnerability, allowing threat actors to bypass traditional disk-based detection methods. This attack has been linked to various malicious activities, including crypto-mining and potentially broader operations.[emaillocker id="1283"]
The attack begins by exploiting a template injection vulnerability in Confluence, allowing unauthorized execution of OGNL objects. A malicious payload is then introduced, loading the Godzilla webshell into memory. Godzilla uses AES encryption to secure communications and employs dynamic class loading to inject a custom valve into the Tomcat server, enabling persistent unauthorized access. The payload includes Base64-encoded anonymous classes, which are decoded and executed in-memory using Java Reflection, making detection by traditional anti-virus solutions particularly difficult. This fileless nature further complicates detection, as the malware resides solely in memory without leaving traces on disk.
Organizations using Atlassian Confluence should prioritize patching their systems to mitigate the risk of this vulnerability being exploited. Additionally, advanced security solutions that provide enhanced threat detection beyond signature-based methods are recommended to defend against fileless malware attacks like Godzilla. By staying proactive with security updates and leveraging modern defense mechanisms, organizations can minimize the risk of compromise from this critical vulnerability.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1505 | Server Software Component |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1620 | Reflective Code Loading | |
| T1055 | Process Injection | |
| T1140 | Deobfuscate/Decode Files or Information | |
| Command and Control | T1573 | Encrypted Channel |
| Exfiltration | T1048 | Exfiltration Over Alternative Protocol |
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://www.trendmicro.com/en_us/research/24/h/godzilla-fileless-backdoors.html