DripDropper Malware Exploits Patched Apache ActiveMQ for Persistence on Cloud Linux Systems (Campaign)
ID: 2fae23a8-21c9-5f92-8f84-3d0d61ee7a7a
STIX ID: report--2fae23a8-21c9-5f92-8f84-3d0d61ee7a7a
Feed Name: Wiz Cloud Threat Landscape
Threat Score
Date Published: 2025-08-19
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
...
...
Threat actors exploited Apache ActiveMQ RCE (CVE-2023-46604) on cloud Linux systems to deploy Sliver C2 and the DripDropper encrypted PyInstaller ELF, modify SSH configuration to enable root and stealthy access, and use Cloudflare Tunnels and Dropbox for command-and-control; attackers then downloaded patched Maven JARs to cover the exploitation trail and hinder detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
