A new backdoor was this week found implanted in the environments of organizations to exploit the recently disclosed critical vulnerability in Atlassian Confluence. The backdoor provides attackers remote access to a victim, both its Confluence server and other network resources, and is found to persist even after Confluence patches are applied. Patches were made available from October 31, with Atlassian telling customers at the time they "must take immediate action". Given the vulnerability was suggested to be under mass exploitation as of November 8, the need to apply patches is stronger than ever. Experts at Aon's incident response provider Stroz Friedberg said the backdoor is a novel piece of malware called Effluence. "The malware is difficult to detect and organizations with Confluence servers are advised to investigate thoroughly, even if a patch was applied," according to the advisory. The web shell is implanted in an atypical way, with malware of this kind usually being uploaded via Confluence's plugin system. In these cases, web shells can only be accessed if the attacker is able to log into Confluence or via an attacker-controlled webpage. In the case observed by the incident responders, Effluence was installed in a way that allowed an unauthenticated attacker to access it. Here, the attacker hijacked the underlying Apache Tomcat webserver and inserted Effluence between it and Confluence, making it available on every web page. Effluence is capable of executing a rich ...
Confluence backdoor ‘Effluence’ persists even after patching
The Register
·Connor Jones
·Published Nov 14, 2023
·Updated
Affected Software
1 affected component
Atlassian Confluence
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of a persistent backdoor named 'Effluence' in Atlassian Confluence that exploits a critical vulnerability.
2
What security implications are discussed?
The article highlights the risk of attackers maintaining remote access to compromised organizations even after patching vulnerabilities.
3
What vulnerabilities are being targeted in this article?
The article focuses on a recently disclosed critical vulnerability in Atlassian Confluence that has been exploited to implant the backdoor.
4
What organizations are affected by this backdoor?
Organizations using Atlassian Confluence are at risk of being compromised by the Effluence backdoor.
5
How does the Effluence backdoor impact Confluence users?
The backdoor allows attackers to gain unauthorized remote access to the Confluence environment, potentially leading to data breaches.