216.73.216.36

Confluence Exploit Leads to LockBit Ransomware

· Published 24/02/2025 06:16 · Modified 24/02/2025 09:09

Export JSON

Essential information

Published
24/02/2025 06:16
Modified
24/02/2025 09:09
Tags
2025-02-24 CVE-2023-22527 confluence credential-theft exfiltration lateral movement lockbit ransomware rdp
Related entities
4 vulnerabilities (cve), 15 observables, 1 intrusion sets (apt), 19 techniques (mitre), 1 malware

Description

An intrusion began with the exploitation of on an exposed Windows server, leading to deployment across the environment. The threat actor utilized various tools including Mimikatz, Metasploit, and AnyDesk. They leveraged for and deployed through multiple methods, including SMB file copying and automated distribution via PDQ Deploy. Sensitive data was exfiltrated using Rclone to MEGA.io cloud storage. The intrusion had a rapid Time to Ransom of approximately two hours, showcasing the efficiency of the attack.

External references