
Support
Aon's Stroz Friedberg Incident Response Services ("Stroz Friedberg") observed the use of novel malware, dubbed "Effluence," in combination with the exploit of a recent Atlassian Confluence vulnerability. Once implanted, the malware acts as a persistent backdoor and is not remediated by applying patches to Confluence. The backdoor provides capability for lateral movement to other network resources in addition to exfiltration of data from Confluence. Importantly, attackers can access the backdoor remotely without authenticating to Confluence. The malware is difficult to detect and organizations with Confluence servers are advised to investigate thoroughly, even if a patch was applied.
Stroz Friedberg was engaged to help a client perform diligence after they discovered that they had a known vulnerable (CVE-2023-22515) Atlassian Confluence Data Center server near the edge of their network. This vulnerability allows an attacker to gain unauthorized access to the administrative areas of a Confluence server.
In this specific client engagement, the cybercriminal gained initial access via the previously mentioned vulnerability and embedded a novel web shell into the Confluence server which allowed them persistent access to every web page on the server without the need for a valid user account. Typical web shells encountered with Confluence exploits are uploaded via the Confluence Plugin ability, e.g., https://github.com/dubfr33/atlassian-webshell-plugin. Such web shells are only accessible if a user has signed into Confluence or if a single webpage of the webserver has been hooked. The attacker must access the exact page of the web shell, for example, http://example.com/webshell.jsp.
The web shell encountered during Stroz Friedberg’s investigation, however, hijacks the underlying Apache Tomcat webserver and silently inserts itself between Confluence and Tomcat–making itself available on every webpage, including the unauthenticated login page. The web shell does not make any changes to the webpages and allows requests to pass through it unnoticed until a request matches specific parameters.
Stroz Friedberg identified this web shell on public malware repositories with no detections, indicating others may be at risk of this malware. Given ongoing attacks against Confluence, this post aims to raise awareness and provide initial detection methods. Public analysis of the inner workings of the malware will be published at a later date.
The web shell is split into two parts, a loader and payload. The loader acts as a normal Confluence plugin but utilizes a modified legitimate Java collections class, similar to IdentityHashMap, to hide its malicious payload. The loader is triggered via an overloaded equals() method, which decrypts the payload into a byte array containing a Java class, then loads that class via reflection—hence the raw Java class is never written to the filesystem. Once the payload is loaded, it runs a function which hides the plugin among Confluence “System Apps”, whereas a user loaded plugin would normally be among “User-Installed Apps”.
The web shell traverses internal structures of the ServletContextFactory interface in order to locate and then add itself to Tomcat’s internal applicationEventListenersList. It implements a ServletRequestListener such that any request to the Confluence server passes through the web shell first, including all pages accessible to unauthenticated users. Because the web shell is available from the login page, attackers can trigger it without needing to maintain Confluence user access. The web shell itself takes no action unless a particular query parameter is supplied. When triggered, the web shell can execute any of the following functions (which closely align with a Godzilla webshell plugin):
To assist in identifying this web shell in an environment, the below includes multiple detections for this web shell. Please take note: at this time, patching Confluence to address CVE-2023-22515 and CVE-2023-22518 will not remediate the web shell if it has been deployed.
This detection looks for plugins created in the Atlassian plugin directories. This will only identify whether a plugin was installed and not whether the plugin is malicious. To identify if a plugin was installed, look for files with a “.jar” extension in any of the following directories:
Due to the customizable nature of Confluence installations, it is prudent to check other Confluence related directories including plugin-cache and bundled-plugins.
Detecting usage of this web shell depends on review of the web server access logs. Due to the method the web shell uses, there are no obvious Indicators of Compromise (IOCs) in the web logs to detect usage of the web shell. However, one may be able to find potential usage by reviewing access to static confluence pages, such as “/login.action”, where the response size varies. For example, the following screenshot shows successful access to “/login.action” with response sizes that vary between 826 to 2574 bytes:
Figure 1 – Examples of malicious requests from logs located at /opt/atlassian/confluence/logs/conf_access_log.log
While we are still gathering information about this particular malware, as an early point of note – Stroz Friedberg recommends baselining your environment to find the normal range of response sizes for the environment to find the abnormal response sizes.
Detection of the web shell via this method relies on a memory capture from the server. Stroz Friedberg developed the following Yara rule which can detect the web shell in the preserved memory image:
rule ConfluencePageIndicator {
meta:
description = "Detects strings indicative of a web shell in Confluence page"
author = "Stroz Friedberg"
date = "2023-11-06"
strings:
$confluence_title = " - Confluence " ascii wide
$hide_plugin_function = "hidePlugin(" ascii wide
$system_plugin_key = "ALWAYS_SYSTEM_PLUGIN_KEYS" ascii wide
$dashes = " ----- " ascii wide
condition:
$confluence_title and $hide_plugin_function and $dashes and $system_plugin_key
}
Support
Stroz Friedberg has not thoroughly tested to what extent this novel malware is applicable to other Atlassian products. Several of the web shell functions depend on Confluence-specific APIs. However, the plugin and the loader mechanism appear to depend only on common Atlassian APIs and are potentially applicable to JIRA, BitBucket, or other Atlassian products where an attacker can install the plugin.
If you suspect you are compromised or need assistance in assessing compromise, please call our Incident Response hotline. If you are from a Law Enforcement Agency or Endpoint Detection and Response vendor and wish for more details, please contact Aon Cyber Solutions.
1 Lightweight Directory Access Protocol
While care has been taken in the preparation of this material and some of the information contained within it has been obtained from sources that Stroz Friedberg believes to be reliable (including third-party sources), Stroz Friedberg does not warrant, represent, or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the article and accepts no liability for any loss incurred in any way whatsoever by any person or organization who may rely upon it. It is for informational purposes only. You should consult with your own professional advisors or IT specialists before implementing any recommendation or following the guidance provided herein. Further, we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. Further, this article has been compiled using information available to us up to 11/8/23.
Support
About Cyber Solutions:
Aon’s Cyber Solutions offers holistic cyber risk management, unsurpassed investigative skills, and proprietary technologies to help clients uncover and quantify cyber risks, protect critical assets, and recover from cyber incidents.
General Disclaimer
This document is not intended to address any specific situation or to provide legal, regulatory, financial, or other advice. While care has been taken in the production of this document, Aon does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the document or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Any recipient shall be responsible for the use to which it puts this document. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document.
Terms of Use
The contents herein may not be reproduced, reused, reprinted or redistributed without the expressed written consent of Aon, unless otherwise authorized by Aon. To use information contained herein, please write to our team.
Our Better Being podcast series, hosted by Aon Chief Wellbeing Officer Rachel Fellowes, explores wellbeing strategies and resilience. This season we cover human sustainability, kindness in the workplace, how to measure wellbeing, managing grief and more.
Expert Views on Today's Risk Capital and Human Capital Issues
Expert Views on Today's Risk Capital and Human Capital Issues
Expert Views on Today's Risk Capital and Human Capital Issues
Better Decisions Across Interconnected Risk and People Issues.
The construction industry is under pressure from interconnected risks and notable macroeconomic developments. Learn how your organization can benefit from construction insurance and risk management.
Stay in the loop on today's most pressing cyber security matters.
Our Cyber Resilience collection gives you access to Aon’s latest insights on the evolving landscape of cyber threats and risk mitigation measures. Reach out to our experts to discuss how to make the right decisions to strengthen your organization’s cyber resilience.
Our Employee Wellbeing collection gives you access to the latest insights from Aon's human capital team. You can also reach out to the team at any time for assistance with your employee wellbeing needs.
Explore Aon's latest environmental social and governance (ESG) insights.
Our Global Insurance Market Insights highlight insurance market trends across pricing, capacity, underwriting, limits, deductibles and coverages.
How do the top risks on business leaders’ minds differ by region and how can these risks be mitigated? Explore the regional results to learn more.
Our Human Capital Analytics collection gives you access to the latest insights from Aon's human capital team. Contact us to learn how Aon’s analytics capabilities helps organizations make better workforce decisions.
Read our collection of human capital articles that explore in depth hot topics for HR and risk professionals, including using data and analytics to measure total rewards programs, how HR and finance can better partner and the impact AI will have on the workforce.
Explore our hand-picked insights for human resources professionals.
Our Workforce Collection provides access to the latest insights from Aon’s Human Capital team on topics ranging from health and benefits, retirement and talent practices. You can reach out to our team at any time to learn how we can help address emerging workforce challenges.
Our Mergers and Acquisitions (M&A) collection gives you access to the latest insights from Aon's thought leaders to help dealmakers make better decisions. Explore our latest insights and reach out to the team at any time for assistance with transaction challenges and opportunities.
The challenges in adopting renewable energy are changing with technological advancements, increasing market competition and numerous financial support mechanisms. Learn how your organization can benefit from our renewables solutions.
How do businesses navigate their way through new forms of volatility and make decisions that protect and grow their organizations?
Our Parametric Insurance Collection provides ways your organization can benefit from this simple, straightforward and fast-paying risk transfer solution. Reach out to learn how we can help you make better decisions to manage your catastrophe exposures and near-term volatility.
Our Pay Transparency and Equity collection gives you access to the latest insights from Aon's human capital team on topics ranging from pay equity to diversity, equity and inclusion. Contact us to learn how we can help your organization address these issues.
Forecasters are predicting an extremely active 2024 Atlantic hurricane season. Take measures to build resilience to mitigate risk for hurricane-prone properties.
Our Technology Collection provides access to the latest insights from Aon's thought leaders on navigating the evolving risks and opportunities of technology. Reach out to the team to learn how we can help you use technology to make better decisions for the future.
Trade, technology, weather and workforce stability are the central forces in today’s risk landscape.
Our Trade Collection gives you access to the latest insights from Aon's thought leaders on navigating the evolving risks and opportunities for international business. Reach out to our team to understand how to make better decisions around macro trends and why they matter to businesses.
With a changing climate, organizations in all sectors will need to protect their people and physical assets, reduce their carbon footprint, and invest in new solutions to thrive. Our Weather Collection provides you with critical insights to be prepared.
Our Workforce Resilience collection gives you access to the latest insights from Aon's Human Capital team. You can reach out to the team at any time for questions about how we can assess gaps and help build a more resilience workforce.
Article 12 mins
As business demands grow more complex, employers must offer a total rewards package that balances the varied needs of the workforce with financial sustainability. Explore ways to ensure an effective total rewards program with data and timely communications.
Article 6 mins
Forecasters predict another above-average North Atlantic hurricane season. Businesses should use their saved premium dollars to strengthen their hurricane-prone properties and workforce, and treat risk management as a strategic asset.
Article 9 mins
The global marine cargo market faces many risks, ranging from shipping delays to geopolitical tensions. These challenges can be mitigated through a risk capital approach, which uses strategic capital allocation and data-driven insights.
Article 8 mins
Ensuring the safe delivery of construction materials along shifting trade channels is no simple endeavor. Learn how specialized insurance and risk management can support the transportation of construction cargo and help ensure project success.
Article 10 mins
With rapid technological advancements, directors and officers face increasing liabilities. Proactive risk management and board oversight can ensure organizational resilience.
Article 13 mins
The FAB industry faces significant supply chain challenges requiring innovative solutions and strategic planning. As organizations work to optimize capital and manage costs, they must also address geopolitical risks and regulatory updates.
Article 9 mins
Industry shifts and innovations are creating both new opportunities and challenges for life sciences organizations. Optimizing risk capital can enable business leaders to uncover cost efficiencies, strengthen resilience and enhance control.
Article 10 mins
In today's uncertain economic climate, finance leaders must innovate beyond traditional financial metrics, managing risk capital through targeted risk strategies, holistic capital approaches and proactive stances toward emerging threats.
Article 6 mins
With looming deadlines on pay transparency regulations, establishing an effective job architecture is foundational to compliance and preparation. We explore how a data-led approach can speed the process while maintaining objectivity.
Report 13 mins
Global business leaders highlight risks linked to trade as some of their top concerns — both physical and financial. While the topic is complex and broad, there are opportunities that business leaders can pursue to stay ahead of emerging trade dynamics.
Article 5 mins
As property underwriters become increasingly concerned and cautious with catastrophe-prone risks, buyers are turning to alternative property solutions, including parametric, to fill protection gaps in their programs.
Article 6 mins
Half of the world’s top economic loss events impacted the U.S. in 2024. As natural catastrophes continue to grow in frequency and severity, enhancing a business continuity strategy helps ensure organizations are prepared for the unexpected.
Article 12 mins
While medical and pharmacy expenses continue to consume benefit budgets, employers can adopt effective cost-saving strategies that combine predictive analytics with innovative solutions to help control healthcare spend over a multi-year period.
Article 8 mins
Employers are increasingly looking to defend the health and safety of their employees in a changing climate. By modeling the impact of weather on employees like they do for physical risks, employers can proactively establish solutions to protect workers.
Article 7 mins
A variety of growing risks, including shareholder derivative actions, an evolving regulatory environment and bankruptcy filings, are why public and private organizations must protect their corporate directors and officers.
Article 15 mins
Organizations in EMEA face unprecedented challenges as cyber threats become more sophisticated. In the face of emerging AI, evolving regulations and geopolitical tensions, businesses should strengthen their resilience to better navigate the complexities of the digital age.
Article 6 mins
In a volatile climate, institutional investors are turning to outsourced chief investment officers to conquer administrative, regulatory and market challenges.
Article 6 mins
Investment in both onshore and offshore wind power is key to not only energy security, but also wider social and economic benefits through the creation of jobs and investments in local communities around the world.
Article 8 mins
In today's intricate business environment, growth is expanding to include more than financial success. By understanding how to fund, shape and secure growth, organizations can build resilience and drive long-term value.
Article 6 mins
AI in the renewable energy sector is revolutionizing how we produce, manage and consume energy. As AI continues to evolve, industry leaders must find innovative ways to harness its full potential.
Article 8 mins
Despite higher claims frequency, the cyber and tech E&O markets remain in a favorable pricing and well-capitalized environment. However, buyers must remain vigilant and manage a variety of current and emerging cyber risks and threat actor attack methods.
Article 4 mins
Organizations can demonstrate their commitment to global sustainability and a low-carbon future by addressing verification challenges and adopting best practices.
Article 15 mins
Market stability prevails in management liability lines as insurers continue to seek market share. However, expanding technologies, increased litigation and macroeconomic factors are causing growing uncertainty and underwriting concerns.
Article 7 mins
There is an opportunity to develop a strategy around financial education in the workplace. Globally, our latest data finds 11 percent of employees receive financial education from their employer, but 37 percent expect it. How can employers bridge this gap?
Article 12 mins
The UK insurance market has seen increased competition and softening conditions. Insurers have capitalized on strong financials and capacity, benefiting buyers. Yet, challenges in specific areas have required strategic engagement and robust risk management for optimal outcomes.
Article 12 mins
With growing global regulations and rising stakeholder and talent expectations, pay equity has shifted from a mere HR initiative to a top C-suite priority that goes beyond compliance.
Article 7 mins
A well-structured open enrollment process is one that leverages innovative technology, encourages cost-effective use of healthcare resources and reduces unnecessary spending — benefiting both employees and employers.
Article 19 mins
While there have been significant strides toward a more inclusive workforce, the gender pay gap persists. Discover how organizations can continue to make progress with interconnected policies and comprehensive programs that support an inclusive environment at every career and life stage.
Article 2 mins
Aon’s Risk Analyzer Suite delivers quantitative analytics, improved risk insights and supports operational efficiency.
Article 15 mins
After a period of significant volatility, a more optimistic outlook is on the horizon for the life sciences industry in 2025. With the right level of preparedness, firms can take full advantage of the potential opportunities the new year will bring.
Article 6 mins
Decarbonizing construction demands new materials and approaches, with a focus on managing risk and securing capital. By aligning sustainability with business strategy and risk management, the industry can meet net-zero targets.
Article 8 mins
Nearly 20 million people get cancer each year,<sup>1</sup> and the impact is far-reaching — from those diagnosed to their loved ones and colleagues. When developing a meaningful cancer prevention strategy, employers must show empathy and compassion while managing rising costs.
Alert 14 mins
In the face of the L.A. wildfires, impacted businesses’ top priority is their people. A three-phased approach can help build business resilience and mitigate the effects of future events.
Article 23 mins
Rapid growth in data center construction, spurred by AI advancements and cloud demand, creates interconnected risks for developers. However, with effective risk management solutions, navigating this dynamic market while prioritizing sustainability is possible.
Article 8 mins
In an industry with tight operating margins, FAB organizations face significant challenges in managing spend and protecting their financial health — requiring industry leaders to adopt a sophisticated approach to risk capital optimization.
Article 15 mins
The risk capital landscape is poised for change, driven by emerging trends reshaping market dynamics. With a buyer-friendly market currently prevailing across most lines, opportunities abound for strategic investment and risk management.
Article 9 mins
When a workers compensation claim goes to litigation, expenses rise dramatically — a burden that is often shouldered by the business. To mitigate attorney-related costs, organizations should re-think their approach to engaging injured workers and use artificial intelligence to enhance outcomes.
Article 35 mins
Human resources is increasingly involved in all areas of a company’s strategy. As the workforce changes, HR leaders should identify and leverage these five important and evolving trends.
Article 6 mins
Long-term care is expensive, and costs are rising due to shortages. With the population aging at the fastest rate in a century, finding solutions to pay for care is an urgent priority. How can employers support this growing population?
Article 7 mins
With a multi-generational and diverse workforce, it is important for employers to develop benefit communications and engagement strategies to help employees understand their unique benefit options. Here are five useful tips to consider.
Article 13 mins
Rising medical costs are a global phenomenon. Aon’s 2025 Global Medical Trend Rate Survey found that costs are projected to rise 10 percent in 2025.
Article 7 mins
As healthcare costs continue to rise, employers are trying to balance the need to take care of their workers with the need to keep costs under control. Aon’s 2025 U.S. Health Survey provides insights into the choices employers are making, and their potential effects on costs.
Article 9 mins
Pension reforms in Europe are reshaping retirement planning, demanding more oversight from employers and new strategies for employees’ financial wellbeing.
Article 6 mins
Non-financial risks are often difficult to predict and quantify, yet present a real threat to financial institutions. In this volatile environment, risk management is playing a greater role in creating business resilience and identifying where capital should be deployed.