Feral Wolf leverages exposed business software and weak server configurations to infiltrate corporate networks, then locks files with ransomware This article explores necessary security teams. . The group targeted Russian organizations in sectors like retail, construction, manufacturing, and IT from May through August 2026.
Analysts at BI.ZONE identified the activity while investigating the intrusions, documenting paths through vulnerable Atlassian Confluence installations, contractor environments, and poorly protected 1C:Enterprise clusters. A separate incident involved a cluster manager operating in debug mode, where its additional functions could be exploited to launch external applications, leaving temporary command files as a potential warning sign. Teams utilizing 1C should enforce stringent cluster administrator authentication, isolate management services from public internet access, and disable debug features unless they are necessary.
Security teams should be vigilant for unexpected administrative changes, suspicious outbound traffic on otherwise permitted protocols, unusual Remote Desktop activity, and the creation of memory dumps. Monitoring across servers, containers, identity systems, and network boundaries can help detect linked actions earlier. This discipline is essential because routine checks can connect internet exposure, configuration changes, administrator behavior, anomalous remote activity, and abnormal internal access before encryption begins.
SHA-256 487886e5058294b7d965421f1d937b721fad95c63374f7dd0570d1b1e9d96c41 memfix.zip SHA-256 2539170c4c1ffeeb17e87917687b5f86104cc88de9478696cee6e0ecaddfc9bb gs-dbus GSocket sample SHA-256 cb5f62bf7b591e69bd38e6bf8e40e8d307d154b2935703422d44f02e403d2e78 gs-dbus GSocket sample SHA-256 1e2e08a36b6126f2363c24b5fe7a6dbd755c35b1cb6f15cdea13fc93274019f3 exploit_cve_2026_31431.py SHA-256 e82ecbe3823046a27d8c39cc0a4acb498f415549946c9ff0e241838b34ed5a21 fscan SHA-256 ccfc37014ce6183bb9268e15e8569fc870e3ccc1123fc2fac9cf43862369f335 GenieLocker sample SHA-256 023a8a4e54dd9264a7d0cca3fd08cae15c661c91bb477dfc08a5c0f9939fb5cb GenieLocker sample SHA-256 588f817d9047f093ee8b68d1d50354a2f5cd5d01451512bdb75d726e61e419fa MQTTDoor SHA-256 c6a0476571cf67255001201be70f6fdfc3ac945515c1c8b327a9a92a4e89991d MatrixDoor SHA-256 b4c7e52bf47f8770683b13c6bdaee80924511673b94a6eb46157dffee8e92d05 RDPSocksProxy












