Mauri Ransomware Threat Actors Exploiting Apache ActiveMQ Vulnerability (CVE-2023-46604)
ID: 863d3d29-b3c0-55e0-8fdd-c642aee53a22
STIX ID: report--863d3d29-b3c0-55e0-8fdd-c642aee53a22
Feed Name: ASEC
Executive summary: ASEC observed active exploitation of Apache ActiveMQ CVE-2023-46604 against unpatched servers—primarily in Korea—where attackers remotely load XML configurations to execute commands. Post-exploitation artifacts include backdoor account creation, Quasar RAT deployments, Frpc reverse-proxy configuration to expose internal RDP (port 3389), coinmining activity, and evidence of Mauri ransomware files; the report provides MD5s, URLs and an IP address as IOCs and urges immediate patching and perimeter restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
