Feral Wolf Ransomware Exploits Confluence

Feral Wolf ransomware leverages exposed Confluence and misconfigured systems

Feral Wolf ransomware has been linked to intrusions through exposed Atlassian Confluence installations and poorly secured 1C:Enterprise clusters. The campaign targeted Russian organisations between May and August 2026 before deploying GenieLocker to encrypt data.

Feral Wolf ransomware campaign targets business systems

BI.ZONE identified the activity while investigating attacks against organisations in the retail, construction, manufacturing and information technology sectors. Rather than relying on one entry technique, the operators combined vulnerable software, stolen or weak credentials, remote access and custom backdoors.

The incidents show how applications that support routine business operations can provide a route into wider corporate networks. Internet-facing collaboration platforms, enterprise management systems and connections maintained by contractors all featured in the observed attack paths.

The reported campaign ran from May through August 2026. The available reporting does not establish that activity stopped after August, so organisations should not interpret the documented period as confirmation that the threat is over.

Who was affected

The known victims were Russian companies operating across several commercial sectors. BI.ZONE’s findings do not provide a complete victim count, identify every affected organisation or indicate that the targeting was limited exclusively to those industries.

The variety of affected sectors suggests that Feral Wolf ransomware operators were interested in accessible corporate environments rather than one narrowly defined type of business. Common enterprise technology and weak external access controls provided opportunities that could be reused across different targets.

How Feral Wolf ransomware gained initial access

One intrusion path involved vulnerable Atlassian Confluence installations exposed to the internet. Confluence is widely used to store internal documentation and support collaboration, making a compromised deployment potentially valuable for both access and intelligence about an organisation.

The reporting does not identify a specific Confluence vulnerability, CVE or affected product version. It also does not state whether every compromised installation was breached through the same flaw. This distinction matters because defenders should not assume that remediation is limited to one patch or release.

Where Confluence was involved, the exposed service acted as an initial foothold from which the attackers could pursue access to the wider environment. An application server may hold service credentials, connect to internal resources or reveal technical information that assists subsequent movement.

Misconfigured 1C:Enterprise clusters

Other cases involved poorly protected 1C:Enterprise clusters. The 1C platform supports business processes such as accounting, finance, sales and operational management, and an insecure cluster can therefore sit close to commercially sensitive systems and data.

BI.ZONE described these environments as misconfigured or insufficiently protected. The available material does not name a particular 1C:Enterprise version or software vulnerability. The reported weakness was associated with configuration and access protection rather than a disclosed product defect with a stated patch level.

Weak or stolen credentials were also part of the Feral Wolf ransomware activity. Credentials can allow an attacker to use legitimate access routes, which may make malicious sessions harder to distinguish from ordinary administration unless authentication and connection activity are closely monitored.

Contractor environments expanded the attack path

BI.ZONE also documented movement through contractor environments. A supplier or contractor may possess remote access, trusted credentials or network connectivity required to support a customer’s systems. If that external environment is compromised, the same access can become a route towards the customer.

This means the initially compromised system was not necessarily owned by the eventual ransomware victim. The campaign demonstrates how access inherited through a commercial relationship can allow an incident to cross organisational boundaries.

From initial compromise to GenieLocker encryption

After obtaining access, the operators used remote access capabilities and custom backdoors to maintain control. A backdoor gives an attacker a persistent method of communicating with a compromised host, while remote access tools can support interactive activity inside the network.

The combination gave the attackers more than a single, temporary entry point. It allowed them to operate after the initial compromise and prepare the environment for the final ransomware stage. The published account does not disclose the names, hashes or detailed functionality of the custom backdoors.

GenieLocker was then deployed to encrypt data. This was the disruptive stage of the Feral Wolf ransomware operation, turning earlier access and network movement into an operational incident by making files unavailable.

The source material does not specify the encryption algorithm, encrypted file extensions, ransom note format, payment demand or whether data was stolen before encryption. It is therefore not possible to conclude from the available evidence that every incident included data theft or a double extortion demand.

Observed attack sequence

Although individual cases followed different entry paths, the reported activity can be summarised as a linked sequence:

  • Attackers identified exposed or poorly protected business applications.
  • Initial access was obtained through vulnerable Confluence installations, insecure 1C:Enterprise clusters, credentials or contractor environments.
  • Remote access and custom backdoors helped the operators retain control.
  • The attackers moved beyond the original point of compromise into corporate systems.
  • GenieLocker ransomware was deployed to encrypt data and disrupt operations.

No specific Confluence or 1C:Enterprise product versions have been confirmed as affected in the reporting. Organisations should base their exposure review on whether these systems are externally reachable, securely configured and fully updated, rather than checking for one named release alone.

Current exploitation status and why it matters

This is observed malicious activity, not a theoretical vulnerability warning. BI.ZONE investigated real intrusions conducted between May and August 2026, with Feral Wolf ransomware reaching the encryption stage against corporate targets.

However, the reporting does not provide a precise number of active operators, a comprehensive indicator list or confirmation that the campaign remains continuously active. It also does not attribute every exposed Confluence or 1C incident to Feral Wolf. Defenders should preserve that distinction when assessing alerts.

The main concern is the way the campaign connected several manageable weaknesses. An exposed application, inadequate server configuration, compromised credential or trusted contractor connection could become the first step in a broader ransomware incident.

Actions tied to the Feral Wolf ransomware activity

Organisations using Confluence or 1C:Enterprise should first establish which deployments are reachable from the internet and whether that exposure is necessary. Reviews should include systems operated by contractors or hosting providers, not only assets managed directly by internal teams.

  • Update supported Confluence deployments and investigate unexplained administrative changes, new accounts and unusual outbound connections.
  • Review 1C:Enterprise cluster authentication, exposed interfaces, administrative permissions and network access restrictions.
  • Reset credentials suspected of exposure and examine remote access logs for unfamiliar sources or unexpected sessions.
  • Validate contractor access routes, restrict them to required systems and confirm that access can be disabled quickly during an incident.
  • Search affected hosts for unauthorised persistence or backdoors before restoring services.

Because the campaign progressed beyond initial access, simply closing an exposed service may not remove an established attacker. If suspicious activity is found, organisations should isolate affected systems, preserve evidence and determine whether remote access, persistence or GenieLocker deployment occurred elsewhere in the environment.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call