logo

Mauri Ransomware Exploiting Apache ActiveMQ (Campaign)

ID: e43f56f7-394d-53e4-b882-12cd28acf79b

STIX ID: report--e43f56f7-394d-53e4-b882-12cd28acf79b

Feed Name: Wiz Cloud Threat Landscape

Threat Score
80/100

Date Published: 2024-12-02

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Mauri ransomware and other malware are being delivered by attackers exploiting Apache ActiveMQ CVE-2023-46604 (OpenWire insecure deserialization). Exploits allow remote loading of malicious XML configs, remote command execution, creation of backdoor accounts, deployment of CoinMiners, Quasar RAT, FRP proxies to expose internal services, and Mauri ransomware that encrypts files with AES-256 CTR; a C2 server (18.139.156.111:4782) is identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.