Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518
Trend AI Research Blog Nov 2023

Cerber Ransomware Exploits Atlassian Confluence Vulnerability CVE-2023-22518

RansomwareDefense Evasion

Cerber ransomware operators were observed rapidly weaponizing CVE-2023-22518, a critical vulnerability in Atlassian Confluence Server, to gain initial access to enterprise environments. The attack chain exploits the improper authorization vulnerability to upload a malicious plugin, establishing a web shell for persistent access before deploying the Cerber ransomware payload. This research documents the speed of exploitation following public disclosure, the full infection chain from Confluence compromise to encryption, and provides detection signatures and mitigation guidance for exposed Confluence instances.