Feral Wolf ransomware has been linked to intrusions through exposed Atlassian Confluence installations and poorly secured 1C:Enterprise clusters. The campaign targeted Russian organisations between May and August 2026 before deploying GenieLocker to encrypt data.
Feral Wolf ransomware campaign targets business systems
BI.ZONE identified the activity while investigating attacks against organisations in the retail, construction, manufacturing and information technology sectors. Rather than relying on one entry technique, the operators combined vulnerable software, stolen or weak credentials, remote access and custom backdoors.
The incidents show how applications that support routine business operations can provide a route into wider corporate networks. Internet-facing collaboration platforms, enterprise management systems and connections maintained by contractors all featured in the observed attack paths.
The reported campaign ran from May through August 2026. The available reporting does not establish that activity stopped after August, so organisations should not interpret the documented period as confirmation that the threat is over.
Who was affected
The known victims were Russian companies operating across several commercial sectors. BI.ZONE’s findings do not provide a complete victim count, identify every affected organisation or indicate that the targeting was limited exclusively to those industries.
The variety of affected sectors suggests that Feral Wolf ransomware operators were interested in accessible corporate environments rather than one narrowly defined type of business. Common enterprise technology and weak external access controls provided opportunities that could be reused across different targets.
How Feral Wolf ransomware gained initial access
One intrusion path involved vulnerable Atlassian Confluence installations exposed to the internet. Confluence is widely used to store internal documentation and support collaboration, making a compromised deployment potentially valuable for both access and intelligence about an organisation.
The reporting does not identify a specific Confluence vulnerability, CVE or affected product version. It also does not state whether every compromised installation was breached through the same flaw. This distinction matters because defenders should not assume that remediation is limited to one patch or release.
Where Confluence was involved, the exposed service acted as an initial foothold from which the attackers could pursue access to the wider environment. An application server may hold service credentials, connect to internal resources or reveal technical information that assists subsequent movement.
Misconfigured 1C:Enterprise clusters
Other cases involved poorly protected 1C:Enterprise clusters. The 1C platform supports business processes such as accounting, finance, sales and operational management, and an insecure cluster can therefore sit close to commercially sensitive systems and data.
BI.ZONE described these environments as misconfigured or insufficiently protected. The available material does not name a particular 1C:Enterprise version or software vulnerability. The reported weakness was associated with configuration and access protection rather than a disclosed product defect with a stated patch level.
Weak or stolen credentials were also part of the Feral Wolf ransomware activity. Credentials can allow an attacker to use legitimate access routes, which may make malicious sessions harder to distinguish from ordinary administration unless authentication and connection activity are closely monitored.
Contractor environments expanded the attack path
BI.ZONE also documented movement through contractor environments. A supplier or contractor may possess remote access, trusted credentials or network connectivity required to support a customer’s systems. If that external environment is compromised, the same access can become a route towards the customer.
This means the initially compromised system was not necessarily owned by the eventual ransomware victim. The campaign demonstrates how access inherited through a commercial relationship can allow an incident to cross organisational boundaries.
From initial compromise to GenieLocker encryption
After obtaining access, the operators used remote access capabilities and custom backdoors to maintain control. A backdoor gives an attacker a persistent method of communicating with a compromised host, while remote access tools can support interactive activity inside the network.
The combination gave the attackers more than a single, temporary entry point. It allowed them to operate after the initial compromise and prepare the environment for the final ransomware stage. The published account does not disclose the names, hashes or detailed functionality of the custom backdoors.
GenieLocker was then deployed to encrypt data. This was the disruptive stage of the Feral Wolf ransomware operation, turning earlier access and network movement into an operational incident by making files unavailable.
The source material does not specify the encryption algorithm, encrypted file extensions, ransom note format, payment demand or whether data was stolen before encryption. It is therefore not possible to conclude from the available evidence that every incident included data theft or a double extortion demand.
Observed attack sequence
Although individual cases followed different entry paths, the reported activity can be summarised as a linked sequence:
- Attackers identified exposed or poorly protected business applications.
- Initial access was obtained through vulnerable Confluence installations, insecure 1C:Enterprise clusters, credentials or contractor environments.
- Remote access and custom backdoors helped the operators retain control.
- The attackers moved beyond the original point of compromise into corporate systems.
- GenieLocker ransomware was deployed to encrypt data and disrupt operations.
No specific Confluence or 1C:Enterprise product versions have been confirmed as affected in the reporting. Organisations should base their exposure review on whether these systems are externally reachable, securely configured and fully updated, rather than checking for one named release alone.
Current exploitation status and why it matters
This is observed malicious activity, not a theoretical vulnerability warning. BI.ZONE investigated real intrusions conducted between May and August 2026, with Feral Wolf ransomware reaching the encryption stage against corporate targets.
However, the reporting does not provide a precise number of active operators, a comprehensive indicator list or confirmation that the campaign remains continuously active. It also does not attribute every exposed Confluence or 1C incident to Feral Wolf. Defenders should preserve that distinction when assessing alerts.
The main concern is the way the campaign connected several manageable weaknesses. An exposed application, inadequate server configuration, compromised credential or trusted contractor connection could become the first step in a broader ransomware incident.
Actions tied to the Feral Wolf ransomware activity
Organisations using Confluence or 1C:Enterprise should first establish which deployments are reachable from the internet and whether that exposure is necessary. Reviews should include systems operated by contractors or hosting providers, not only assets managed directly by internal teams.
- Update supported Confluence deployments and investigate unexplained administrative changes, new accounts and unusual outbound connections.
- Review 1C:Enterprise cluster authentication, exposed interfaces, administrative permissions and network access restrictions.
- Reset credentials suspected of exposure and examine remote access logs for unfamiliar sources or unexpected sessions.
- Validate contractor access routes, restrict them to required systems and confirm that access can be disabled quickly during an incident.
- Search affected hosts for unauthorised persistence or backdoors before restoring services.
Because the campaign progressed beyond initial access, simply closing an exposed service may not remove an established attacker. If suspicious activity is found, organisations should isolate affected systems, preserve evidence and determine whether remote access, persistence or GenieLocker deployment occurred elsewhere in the environment.
Originally reported by cybersecuritynews.com.






