TTO-2026-0919-142 · September 19, 2026 Ransomware

Feral Wolf Ransomware Group Deploys GenieLocker via Atlassian Confluence and Misconfigured 1C:Enterprise Against Russian Organizations

BI.ZONE researchFeral Wolf threat actorGenieLocker ransomwareMatrixDoor Rust backdoorCVE-2023-22515 Atlassian Confluence1C:Enterprise cluster misconfigurationRussian retail / construction / manufacturing / ITMay-August 2026

Summary

BI.ZONE has published research on Feral Wolf, a threat actor that conducted ransomware campaigns against Russian organizations in retail, construction, manufacturing, and information technology from May through August 2026. Feral Wolf gained initial access through two distinct paths: exploitation of CVE-2023-22515, a known critical privilege escalation vulnerability in Atlassian Confluence, and abuse of authentication weaknesses in internet-exposed 1C:Enterprise business management software clusters. After establishing access, the group deployed a previously undocumented Rust-based backdoor called MatrixDoor, used a suite of tunneling and remote access tools, and ultimately encrypted victim data using GenieLocker ransomware.

Timeline

DateEvent
May-August 2026Feral Wolf conducts ransomware intrusions against Russian organizations across four sectors; BI.ZONE investigates multiple incidents
Sep 18, 2026BI.ZONE publishes full technical analysis including MatrixDoor backdoor details, GenieLocker, and dual initial access paths

What Happened

In one documented intrusion, Feral Wolf exploited CVE-2023-22515, an Atlassian Confluence privilege escalation vulnerability patched in October 2023, against a publicly accessible Confluence server running inside a Docker container behind a proxy. After exploiting the vulnerability to create an administrator account, the attackers installed a malicious Confluence plugin providing command execution within the container. They deployed GSocket, a reverse-connection utility disguised as Linux kernel processes ([kcached] and [rcu_preempt]), to establish persistent remote access. Using credentials discovered in the container environment, they pivoted from Docker container to underlying host through a weakly-authenticated PostgreSQL service and continued lateral movement across the internal network.

A second initial access path targeted internet-exposed 1C:Enterprise cluster management services where authentication was absent or disabled. Where cluster administration was unprotected, Feral Wolf connected directly to the management service and executed operating system commands via specially prepared 1C database content or external processing files. In a separate case involving a cluster in debug mode, the group abused extended debug functions to launch external applications.

After establishing access, Feral Wolf deployed MatrixDoor, a Rust-based backdoor distributed as wtas.exe enabling remote command execution via CMD interpreter. Additional tooling included revsocks for traffic tunneling through existing RDP sessions and MQTT- and Matrix-based C2 channels that blend into legitimate enterprise traffic patterns. Credential harvesting included LSASS memory dumps. GenieLocker ransomware was the final payload in affected environments.

Note on Domain Intelligence

Feral Wolf is a ransomware threat actor targeting Russian organizations across multiple sectors. No single vendor or victim domain is the subject of this bulletin. Domain intelligence for specific targeted organizations is available at warmbadge.com where those domains have been evaluated.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 19, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026