Gbhackers iconGbhackersSep 18, 2026

Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware

Feral Wolf has expanded its ransomware tradecraft by abusing exposed Atlassian Confluence servers and insecure 1C:Enterprise deployments to gain access to Russian corporate networks before deploying GenieLocker ransomware.

Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware

Share this story

Send the public story page.

Useful takeaways from this story.

Feral Wolf has expanded its ransomware tradecraft by abusing exposed Atlassian Confluence servers and insecure 1C:Enterprise deployments to gain access to Russian corporate networks before deploying...

BI.ZONE DFIR investigators found that the threat actor combined […]

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Feral Wolf has expanded its ransomware tradecraft by abusing exposed Atlassian Confluence servers and insecure 1C:Enterprise deployments to gain access to Russian corporate networks before deploying GenieLocker ransomware. BI.ZONE DFIR investigators found that the threat actor combined […]

Details worth keeping

BI.ZONE DFIR investigators found that the threat actor combined […]

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app