Credential Phishing Attack Hosted on Atlassian Confluence

Credential phishing links are most commonly sent by email, and they typically lead to a website that is designed to look like common applications—most notably Microsoft Office 365, Google, Amazon, or other well-known...
September 23, 2021

Credential phishing links are most commonly sent by email, and they typically lead to a website that is designed to look like common applications—most notably Microsoft Office 365, Google, Amazon, or other well-known brands. A rising trend is attackers frequently like to use links leading to shared documents on Google Docs or Dropbox to steal credentials.

This attack is the first we’ve observed hosted on a Confluence page and while much less common, shows how attackers are willing to try nearly everything to steal your information and money.

Summary of Attack Target

  • Target: Prominent Healthcare System
  • Platform: Office 365
  • Victims: Hospital Administrators
  • Payload: Phishing Link
  • Technique: Credential Theft

About the Confluence Phishing Attempt

Utilizing the compromised account of a trusted lawyer out of a notable firm, cybercriminals began their spear-phishing campaign by attacking an equally noteworthy health care system. This may have been an attempt to steal valuable personal information—something that is highly prevalent in healthcare systems and makes them a prime target for attack.

The spear-phishing, or highly targeted, email disguised the malicious web page with a seemingly innocent RFP—a new method of attack that has seen increasing use over the last year. The use of the phrases secure link and please do not share this email offer a sense of security and trustworthiness, indicative of suspicious behavior.

Confluence spear phishing attack email

Once the link is clicked, the recipient is taken to a Confluence web page where the malicious file is stored. Here, the recipient is greeted with more suspicious wording including SECURE FILE and This document is protected for your view only. By attempting to create a relationship of trust and security with the recipient, attackers are able to successfully entice recipients to click on the malicious links.

Confluence attack landing

While the malicious OPEN HERE link was removed prior to Abnormal investigating this email, we can determine that it was likely leading users to a phishing website where they would be required to enter their credentials to their Office 365 account in order to see the RFQ. Email credentials are typically the most valued by threat actors, as they can hijack existing conversations and send additional phishing emails from the compromised account.

Alternatively, this link could have led to an impersonated Confluence page, where the user would enter their Confluence credentials in order to access the PDF. Once entered, the threat actor would have access to the organization’s Confluence workspace where they could view all internal documentation about the healthcare organization and potentially gain access to other, more private systems that contained personal patient information.

Why the Confluence Attack Bypassed Existing Security Infrastructure

Attackers are constantly looking for new ways to compromise targets and are adapting their methods to seem more official and real. Atlassian Confluence is one of many different applications that are used throughout the professional world and is one way that teams create and collaborate across a network of distributed employees.

Confluence is best known as a place to organize and share work, and while it is not used solely for file sharing, that is a key component of the system. Attackers took advantage and staged the malicious payload under the guise of an application that they knew the target would recognize. In addition, placing the phishing link on another site allowed the original email to bypass traditional security systems, which typically look only at the first link to determine malicious intent.

Despite the attempt cybercriminals made, Abnormal Security was able to detect several different indicators that the email was likely an attack.

Confluence attack analysis

Abnormal detected the unusual sender domain and the fact that all recipients were bcc’d—a common technique of attackers. Furthermore, Abnormal noticed the suspicious link, which redirected to another webpage. These different facets of attack, alongside thousands of other signals, were detected through the behavioral models and AI technology on which the Abnormal platform is built.

While Abnormal stopped this attack for the healthcare system, other recipients who were bcc’d may have fallen victim to this credential phishing attempt, particularly if their organizations regularly use Confluence for documentation. This attack would be particularly effective for organizations that regularly communicate with the original sender and who may be expecting an RFQ to be sent from them.

Are you prepared to stop credential phishing attacks from compromised accounts? See how Abnormal can help by requesting a demo today.

Credential Phishing Attack Hosted on Atlassian Confluence

See Abnormal in Action

Get a Demo

Get the Latest Email Security Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.


See the Abnormal Solution to the Email Security Problem

Protect your organization from the full spectrum of email attacks with Abnormal.

Integrates Insights Reporting 09 08 22

Related Posts

B Earn Your CPE Credits with Abnormal
Earn your continuing education credits with ISC2 by viewing cybersecurity content from Abnormal Security.
Read More
B Seg Lessons
Discover key insights gleaned from replacing 100+ SEGs for Abnormal customers.
Read More
B Europe Attack Data Blog
Discover what our research uncovered about the European threat landscape and attack trends for organizations in the region.
Read More
Abnormal aims to provide superior detection of email attacks while also directly and indirectly influencing the security awareness of your employees.
Read More
B 6 3 24 BEC Attacks
Discover how cybercriminals obtain corporate data from brokers like ZoomInfo and Apollo to enable targeted business email compromise (BEC) attacks.
Read More
B Addressing Account Takeovers Blog
Discover how security leaders are protecting their organizations against account takeover with insights from our survey of 300 cybersecurity stakeholders.
Read More