News: 1699959606

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Novel backdoor persists even after critical Confluence vulnerability is patched

(2023/11/14)


A new backdoor was this week found implanted in the environments of organizations to exploit the recently disclosed critical vulnerability in Atlassian Confluence.

The backdoor provides attackers remote access to a victim, both its Confluence server and other network resources, and is found to persist even after Confluence patches are applied.

Patches were made available from October 31, with Atlassian [1]telling customers at the time they "must take immediate action". Given the vulnerability was suggested to be under [2]mass exploitation as of November 8, the need to apply patches is stronger than ever.

[3]

Experts at Aon's incident response provider Stroz Friedberg said the backdoor is a novel piece of malware called Effluence.

[4]

[5]

"The malware is difficult to detect and organizations with Confluence servers are advised to investigate thoroughly, even if a patch was applied," according to the [6]advisory .

The web shell is implanted in an atypical way, with malware of this kind usually being uploaded via Confluence's plugin system. In these cases, web shells can only be accessed if the attacker is able to log into Confluence or via an attacker-controlled webpage.

[7]

In the case observed by the incident responders, Effluence was installed in a way that allowed an unauthenticated attacker to access it. Here, the attacker hijacked the underlying Apache Tomcat webserver and inserted Effluence between it and Confluence, making it available on every web page.

Effluence is capable of executing a rich array of commands, many that align with those of the Godzilla web shell, which [8]according to Unit 42 by Palo Alto Networks, is one that's designed to stealthily maintain access on high-interest networks.

A small selection of Effluence's capabilities:

Create a new admin account

Run any command on the host server

Delete and edit files

Deploy additional plugins that could offer more features or vulnerabilities to exploit

Change user passwords

Log credentials at each login attempt

Detecting and remediating Effluence installations isn't entirely straightforward and will require some manual review on the defender's part.

Stroz Friedberg recommends manually reviewing installed plugins for malicious activity. Files with .jar extensions in the following directories, as well as other Confluence-related paths, will indicate if a plugin was installed but this won't indicate whether it's malicious or not:

<confluence_install_dir>/temp/</confluence_install_dir>

<confluence_app_dir>/application_data/plugins-osgi-cache/transformed-plugins/</confluence_app_dir>

<jira_app_dir>/application_data/plugins/installed-plugins/</jira_app_dir>

<bitbucket_app_dir>/application_data/shared/plugins/installed-plugins/</bitbucket_app_dir>

Adding to the difficulty, Effluence doesn't leave behind any indicators of compromise (IOCs). Defenders may find evidence of use when reviewing static confluence pages, monitoring the response size in relation to the organization's baseline range.

[9]Atlassian cranks up the threat meter to max for Confluence authorization flaw

[10]You can buy personal info of US military staff from data brokers for just 12 cents a pop

[11]T-Mobile US exposes some customer data – but don't call it a breach

[12]Stop what you're doing and patch this critical Confluence flaw, warns Atlassian

The advisory also includes a Yara rule that can detect Effluence use in the preserved memory image.

"Stroz Friedberg has not thoroughly tested to what extent this novel malware is applicable to other Atlassian products," it said. "Several of the web shell functions depend on Confluence-specific [13]APIs . However, the plugin and the loader mechanism appear to depend only on common Atlassian APIs and are potentially applicable to JIRA, BitBucket, or other Atlassian products where an attacker can install the plugin." ®

Get our [14]Tech Resources



[1] https://www.theregister.com/2023/10/31/critical_atlassian_confluence_flaw/

[2] https://www.theregister.com/2023/11/08/atlassian_confluence_flaw_upgraded/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZVOntVVCSkg3zO2C1h68KQAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVOntVVCSkg3zO2C1h68KQAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVOntVVCSkg3zO2C1h68KQAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.aon.com/cyber-solutions/aon_cyber_labs/detecting-effluence-an-unauthenticated-confluence-web-shell/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVOntVVCSkg3zO2C1h68KQAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://unit42.paloaltonetworks.com/manageengine-godzilla-nglite-kdcsponge/

[9] https://www.theregister.com/2023/11/08/atlassian_confluence_flaw_upgraded/

[10] https://www.theregister.com/2023/11/07/data_brokers_military_data/

[11] https://www.theregister.com/2023/09/25/tmobile_exposes_some_customer_data/

[12] https://www.theregister.com/2023/10/31/critical_atlassian_confluence_flaw/

[13] https://www.theregister.com/2022/05/25/why_apis_matter/

[14] https://whitepapers.theregister.com/



An Ada exception is when a routine gets in trouble and says
'Beam me up, Scotty'.