CyberSecurity SEE

Feral Wolf Hackers Exploit Confluence and 1C for GenieLocker Ransomware Deployment

Feral Wolf Hackers Exploit Confluence and 1C for GenieLocker Ransomware Deployment

Feral Wolf Expands Ransomware Tactics via Atlassian Confluence and 1C:Enterprise Exploits

In a significant escalation of their ransomware operations, the cybercriminal group known as Feral Wolf has begun leveraging vulnerabilities in exposed Atlassian Confluence servers, along with insecure configurations within 1C:Enterprise deployments. This breach strategy has enabled attackers to infiltrate Russian corporate networks, culminating in the deployment of the GenieLocker ransomware. This emerging trend underscores the persistent threat posed by ransomware actors who capitalize on specific software weaknesses to gain unauthorized access to critical infrastructures.

The campaign has been actively monitored from May to August 2026 and predominantly targeted entities across various sectors, including retail, construction, manufacturing, and information technology. Investigators from BI.ZONE’s Digital Forensics and Incident Response (DFIR) team have been closely tracking these incursions, revealing a multifaceted approach that incorporates the exploitation of public-facing applications, credential abuse, and lateral movements throughout networks via advanced techniques.

Among the tactics utilized, Feral Wolf adeptly exploited an internet-accessible Atlassian Confluence instance that was operating within a Docker container environment. They took advantage of a specific vulnerability, CVE-2023-22515, after initially reaching the environment through a proxy server. Following this initial compromise, the attackers created a new administrative account and deployed a malicious plugin into the system, thereby gaining enhanced capabilities to execute commands. This included the installation of GSocket, a reverse-connection utility designed for maintaining persistent access to compromised systems.

The malware employed, cleverly disguised as benign Linux kernel-related processes, effectively blended in with legitimate network activity by utilizing common ports such as port 53, which is typically used for DNS services. This tactic allowed malicious traffic to avoid detection amidst splashes of normal operational data. Additionally, a backup instance of GSocket was installed, ensuring redundancy for the attackers should their primary access be compromised.

Following the infiltration, Feral Wolf employed several exploitation strategies, including uploads for known vulnerabilities such as PwnKit (CVE-2021-4034) and Copy Fail (CVE-2026-31431). The latter is particularly noteworthy as it can enable an attacker to extend their reach from a container to the underlying host system if certain conditions are met. Feral Wolf also harnessed the fscan reconnaissance tool to identify additional vulnerable services and exploit weak credentials; in one instance, access was gained to a PostgreSQL service protected by the easily guessable password "12345678."

With access established, the attackers deployed revsocks to tunnel communications and efficiently transitioned from the container to the Docker host using the compromised PostgreSQL database credentials. Key among the threats introduced during this phase was the MatrixDoor backdoor, developed in Rust and disguised as wtas.exe, which enabled remote command execution via the Windows CMD interpreter.

Feral Wolf further entrenched their presence on the compromised hosts by modifying shell-profile files and creating scheduled tasks through PostgreSQL cron jobs. This persistence strategy ensured their continued access and control over the systems.

A separate strand of the attack specifically targeted externally accessible 1C:Enterprise server clusters. Here, Feral Wolf successfully connected to exposed cluster-manager services and exploited debug-mode configurations, allowing them to execute administrative commands without proper authentication. They wielded tools that included database dumps from 1C-Shell and malicious processing files to issue operating system commands directly through the 1C platform.

Despite attempts to deploy PrintSpoofer for local privilege escalation, these efforts were thwarted due to lack of the necessary permissions on the compromised account. Instead, the group employed legitimate tools, such as Magnet DumpIt and MemProcFS, to extract credentials from memory, minimizing the risk of detection typically associated with more overt credential-dumping malware.

The campaign’s arsenal extended to three notable tools: MQTTDoor, MatrixDoor, and RDPSocksProxy. Each of these tools plays a crucial role in their operations, providing functionalities ranging from command execution to proxy tunneling, thus offering attackers versatile deployment options while maintaining stealth.

In closing, the culmination of Feral Wolf’s operations led to the deployment of GenieLocker ransomware, encrypting data across compromised environments. To counter these threats effectively, BI.ZONE strongly recommends immediate actions: organizations must promptly patch exposed Confluence deployments, restrict external access to vulnerable 1C management services, enforce robust PostgreSQL credentials, and carefully review 1C debug-mode settings to prevent similar incursions. Vigilance is paramount, and security teams should actively search for telltale signs of intrusion, such as unexpected service names and irregular traffic patterns related to public MQTT or Matrix services.

Overall, this wave of ransomware activity serves as a stark reminder of the critical importance of maintaining robust cybersecurity measures and ensuring that systems are fortified against the sophisticated tactics employed by groups like Feral Wolf.

Source link

Exit mobile version