216.73.217.98

Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence

· Published 02/09/2024 16:06 · Modified 02/09/2024 16:20

Export JSON

Essential information

Published
02/09/2024 16:06
Modified
02/09/2024 16:20
Tags
2024-09-02 CVE-2023-22527 aes encryption atlassian confluence fileless backdoor godzilla in-memory remote code execution
Related entities
1 vulnerabilities (cve), 7 techniques (mitre), 1 malware

Description

Trend Micro researchers have identified a new attack vector exploiting in older versions of Data Center and Server. The attack deploys an known as the webshell, which uses for communication and remains memory-resident to evade disk-based detection. The vulnerability allows unauthenticated attackers to perform . The attack chain involves exploiting the vulnerability, loading a loader into the victim server, and activating the webshell. This sophisticated Chinese-language backdoor poses significant challenges for legacy anti-virus solutions, highlighting the importance of regular server patching and advanced security measures.

External references