
Feral Wolf has targeted Russian organizations through exposed Confluence servers, insecure 1C configurations, and compromised contractors, ultimately deploying ransomware. The campaign exploited the Atlassian Confluence vulnerability CVE-2023-22515.
What is the threat?
Feral Wolf is a financially motivated ransomware group that targets organizations by exploiting exposed enterprise systems, weak configurations, and vulnerable software. The group conducts extensive reconnaissance, establishes covert access, works to hide its activity, and deploys GenieLocker ransomware.
Why is it noteworthy?
The group routes command-and-control traffic through MQTT, Matrix, and RDP-based tunnels to blend in with legitimate activity, making detection more difficult. Attackers also use anti-forensic tools and scripts to clear logs, command-line history, and other key artifacts, which can hinder incident response and investigations.
A successful attack can lead to network-wide compromise, business disruption, data encryption, loss of forensic evidence, and extended recovery efforts.
What is the exposure or risk?
The risk stems from a combination of vulnerabilities and weak security practices. CVE-2023-22515 provides initial access through Confluence, while CVE-2021-4034 and CVE-2026-31431 enable privilege escalation after attackers gain access to a host.
In the reported activity, attackers also exploited poorly secured 1C:Enterprise systems and weak database credentials. This demonstrates that patching alone is not enough when administrative interfaces remain exposed or lack authentication.
What are the recommendations?
Barracuda recommends the following actions to reduce the likelihood and impact of an attack:
- Patch or upgrade affected Confluence Server and Data Center instances, and investigate for unauthorized accounts or plugins.
- Update Linux kernels and polkit packages to remediate CVE-2021-4034 and CVE-2026-31431.
- Remove direct internet exposure for Confluence, 1C cluster managers, databases, and administrative services where possible.
- Enforce strong authentication for 1C:Enterprise, PostgreSQL, and other administrative interfaces.
- Review Docker, PostgreSQL, and host/network isolation controls to prevent container-to-host movement.
References
For more in-depth information about the recommendations, please visit the following links:
- https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/
- https://www.sentinelone.com/vulnerability-database/cve-2021-4034/
- https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html
If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.
This post originally appeared on Smarter MSP.

