logo

Apache ActiveMQ Exploit Leads to LockBit Ransomware

ID: 0296c57e-e20e-5cbf-b706-f0c784b0ae8f

STIX ID: report--0296c57e-e20e-5cbf-b706-f0c784b0ae8f

Feed Name: The DFIR Report

Threat Score
75/100

Date Published: 2026-02-23

Date Updated: 2026-04-19

Author: editor

...
...

This DFIR report describes a mid‑Feb 2024 intrusion where a threat actor exploited CVE-2023-46604 against an exposed Apache ActiveMQ server to achieve RCE, delivered a Metasploit/Meterpreter stager, dumped LSASS to harvest credentials, performed lateral movement (remote services, RDP, AnyDesk), and—on a subsequent return 18 days later—used harvested credentials to deploy LockBit ransomware across multiple systems; the report contains technical telemetry, file/host indicators, YARA/Sigma detections, and a timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.