# What happened
# How the intrusions began
Separately, attackers abused 1C:Enterprise cluster management services that were exposed and not protected by strong authentication. In some cases a cluster manager was left in debug mode, which provides extra functions that can launch external applications and leave temporary command files—an observable symptom if monitored.
# Post-exploitation and persistence
After gaining footholds, Feral Wolf used custom backdoors that communicate over MQTT and Matrix, and a proxy utility that tunnels traffic through an existing RDP session. By using common protocols and RDP-based tunneling, they made command-and-control traffic resemble normal network activity.
Techniques used during lateral movement and persistence included:
- A PowerShell script intended to erase forensic traces.
- Creation of covert channels that blend with allowed outbound traffic.
The campaign culminated in deployment of GenieLocker ransomware once they had the necessary access and credential material.
# Concrete indicators and patterns
BI.ZONE published at least one IP indicator tied to the Confluence intrusion: 45.151.45[.]31. The observable chain in multiple incidents was: public app exploit or exposed management → account creation or admin actions → weak-credential access to database services → container-to-host command execution → internal scanning and credential harvesting → covert C2 and tunneling → encryption.
# Practical defensive steps
- Patch Confluence promptly for CVE-2023-22515 and other known vulnerabilities.
- Remove unnecessary public access to collaboration platforms and management interfaces.
- Require strong, unique credentials and multifactor authentication for cluster administrators.
- Keep 1C cluster administration interfaces off the public internet and disable debug features where not required.
- Monitor for unexpected administrative account changes and unusual proxy or RDP activity.
- Watch for outbound traffic over MQTT, Matrix, or other allowed protocols that don't match normal patterns.
- Detect memory-dumping activity and creation of temporary command files as potential early warnings.
- Treat exposed internet-facing business software with the same patching and review cadence as core systems.
# Bottom line
These incidents show a familiar but important point: a single overlooked internet-facing application or misconfigured management service can provide a direct path to broader network compromise. Closing exposed entry points, enforcing strong administrative controls, segmenting networks, and monitoring for covert-but-permitted traffic reduce the chance that an initial application breach becomes a ransomware event.