Cybersecuritynews iconCybersecuritynewsSep 18, 2026 ~6 min source read

Feral Wolf used exposed Confluence and misconfigured 1C clusters to deploy GenieLocker ransomware

Between May and August 2026, investigators linked a series of Russian-targeted ransomware intrusions to exploitation of internet-facing Atlassian Confluence instances and poorly protected 1C:Enterprise clusters, followed by covert command channels, credential theft, and deployment of GenieLocker.

Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems

Share this story

Send the public story page.

Useful takeaways from this story.

The campaign shows how one overlooked internet-facing system can become the starting point for a much larger incident.

Its operators combined exploitation, stolen or weak credentials, remote access, and custom backdoors before deploying GenieLocker to encrypt data.

The investigation is a reminder that ransomware is rarely a single-event failure.

# What happened

# How the intrusions began

Separately, attackers abused 1C:Enterprise cluster management services that were exposed and not protected by strong authentication. In some cases a cluster manager was left in debug mode, which provides extra functions that can launch external applications and leave temporary command files—an observable symptom if monitored.

# Post-exploitation and persistence

After gaining footholds, Feral Wolf used custom backdoors that communicate over MQTT and Matrix, and a proxy utility that tunnels traffic through an existing RDP session. By using common protocols and RDP-based tunneling, they made command-and-control traffic resemble normal network activity.

Techniques used during lateral movement and persistence included:

  • A PowerShell script intended to erase forensic traces.
  • Creation of covert channels that blend with allowed outbound traffic.

The campaign culminated in deployment of GenieLocker ransomware once they had the necessary access and credential material.

# Concrete indicators and patterns

BI.ZONE published at least one IP indicator tied to the Confluence intrusion: 45.151.45[.]31. The observable chain in multiple incidents was: public app exploit or exposed management → account creation or admin actions → weak-credential access to database services → container-to-host command execution → internal scanning and credential harvesting → covert C2 and tunneling → encryption.

# Practical defensive steps

  • Patch Confluence promptly for CVE-2023-22515 and other known vulnerabilities.
  • Remove unnecessary public access to collaboration platforms and management interfaces.
  • Require strong, unique credentials and multifactor authentication for cluster administrators.
  • Keep 1C cluster administration interfaces off the public internet and disable debug features where not required.
  • Monitor for unexpected administrative account changes and unusual proxy or RDP activity.
  • Watch for outbound traffic over MQTT, Matrix, or other allowed protocols that don't match normal patterns.
  • Detect memory-dumping activity and creation of temporary command files as potential early warnings.
  • Treat exposed internet-facing business software with the same patching and review cadence as core systems.

# Bottom line

These incidents show a familiar but important point: a single overlooked internet-facing application or misconfigured management service can provide a direct path to broader network compromise. Closing exposed entry points, enforcing strong administrative controls, segmenting networks, and monitoring for covert-but-permitted traffic reduce the chance that an initial application breach becomes a ransomware event.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app