Cloudflare has confirmed that it was targeted by the advanced persistent threat (APT) group known as Spook. The attack, which occurred between October 26 and October 30, 2023, involved Spook gaining unauthorized access to Cloudflare's internal Atlassian server. This server hosted Cloudflare's Confluence wiki, Jira bug-tracking system, and Bitbucket source code management system.
Spook exploited a zero-day vulnerability in Atlassian Confluence, identified as CVE-2023-22527, to establish initial access. This vulnerability, a critical authentication bypass, allowed the attackers to create a new administrator account on the Confluence instance. Cloudflare's internal security systems detected the breach on October 30, triggering an immediate response.
Upon detection, Cloudflare's security team, Cloudforce One, initiated an investigation. The company confirmed that the attackers were able to access a limited number of systems. Specifically, Spook gained access to the Atlassian server and, from there, attempted to pivot to Cloudflare's self-hosted GitLab server. The attackers also attempted to access a console server that was not connected to Cloudflare's production network.
Cloudflare stated that the attackers used a "sophisticated social engineering campaign" to obtain credentials, though the specifics of this campaign were not detailed. The company's investigation revealed that the attackers downloaded a limited amount of data, including documentation and source code, from the compromised Atlassian and GitLab instances. However, Cloudflare emphasized that its customer data, production systems, and global network were not impacted by the breach.
The company also confirmed that no customer data, including Cloudflare's network logs, was accessed or exfiltrated. The attackers were unable to gain access to Cloudflare's production network or its global network infrastructure. Cloudflare's security measures, including its use of hardware security keys for authentication, were credited with preventing further lateral movement by the attackers.
Cloudflare has since patched the exploited Confluence vulnerability and implemented additional security enhancements. The company also rotated all potentially compromised credentials and rebuilt the affected systems. Cloudflare's incident response included notifying law enforcement and working with external cybersecurity experts to ensure the integrity of its systems.
Spook, also known as APT41, Blackfly, or Winnti, is a state-sponsored hacking group with a history of targeting technology companies and government entities. The group is known for its sophisticated tactics and its ability to exploit zero-day vulnerabilities. Cloudflare's confirmation of the attack by Spook highlights the ongoing threat posed by advanced persistent threat groups to critical infrastructure and technology providers.






