The Feral Wolf ransomware group has been exploiting business software vulnerabilities and weak server configurations to infiltrate corporate networks, subsequently encrypting files as part of a broader ransomware campaign. This situation highlights the significant risks posed by overlooked internet-facing systems, which can serve as entry points for extensive security breaches.
Targeted Sectors and Methodology
Between May and August 2026, Feral Wolf focused on Russian companies across sectors such as retail, construction, manufacturing, and IT. The attackers used a combination of vulnerabilities, compromised credentials, remote access tools, and custom backdoors to deploy their encryption tool, GenieLocker.
BI.ZONE analysts, while investigating these incidents, uncovered how the group leveraged weaknesses in Atlassian Confluence installations, contractor environments, and inadequately secured 1C:Enterprise clusters. This underscores the necessity of giving external services the same security attention as core systems.
Intrusion Techniques and Exploited Vulnerabilities
Feral Wolf’s operations often began with exploiting publicly accessible Confluence servers, manipulating vulnerabilities like CVE-2023-22515. By creating administrative accounts within Confluence, they established a foothold, enabling network exploration and further exploitation of weak systems like PostgreSQL services.
Insecure 1C:Enterprise server clusters further facilitated their attacks. Where cluster management was inadequately protected, attackers executed administrative actions without authentication, using specially crafted database content to run operating-system commands.
Defense Evasion and Recommendations
The group employed advanced backdoors using MQTT and Matrix protocols alongside proxy utilities, making it challenging to distinguish their command-and-control traffic from regular network activity. Legitimate utilities collected system memory, seeking credential data, while attempts to erase forensic evidence were made using PowerShell scripts.
To mitigate such threats, organizations should promptly patch Confluence, restrict unnecessary public access, and regularly review admin accounts. Strong authentication for 1C clusters and restricted management service access are crucial, as is disabling debug functions unless necessary. Monitoring unexpected administrative changes and suspicious traffic is imperative.
Conclusion and Future Precautions
This investigation serves as a stark reminder that ransomware incidents are not isolated failures. Feral Wolf’s strategy of exploiting known vulnerabilities, configuration lapses, and stealing credentials underscores the importance of proactive defense measures. Regular audits and monitoring can help identify potential threats before they escalate into full-blown attacks.
Identifying and securing exposed entry points and tracking subsequent movements are vital to halting ransomware attacks before they reach the critical encryption phase. Maintaining vigilance over routine internet exposures, configuration changes, and administrative behaviors is essential for effective network security.
