Lilac Typhoon is a China-attributed threat actor exploiting Confluence CVE-2022-26134 for cryptojacking and financially motivated attacks.
Analyst brief
Lilac Typhoon (DEV-0234) is a threat actor attributed to China, known for leveraging the Atlassian Confluence RCE vulnerability CVE-2022-26134. Their operations target vulnerable internet-facing Confluence servers for cryptojacking and other financially motivated campaigns. Key TTPs involve deploying Cobalt Strike, web shells, botnets, coin miners, and ransomware via this exploit. Defenders must prioritize patching CVE-2022-26134 and monitor for exploitation frameworks delivering post-compromise tooling.
Lilac Typhoon
DEV-0234
unknown
Lilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which allows for remote code execution. This vulnerability has been used in cryptojacking campaigns and is included in commercial exploit frameworks. Lilac Typhoon has also been involved in deploying various payloads such as Cobalt Strike, web shells, botnets, coin miners, and ransomware.