logo

Case of ActiveMQ Vulnerability Exploitation to Install Sharpire (Kinsing)

ID: b2c36655-aab5-5b9a-936c-5e49004f8287

STIX ID: report--b2c36655-aab5-5b9a-936c-5e49004f8287

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-10-27

Date Updated: 2026-04-26

Author: ATCP

...
...

Kinsing (H2Miner) actors are actively exploiting Apache ActiveMQ CVE-2023-46604 to deploy downloaders, coinminers (XMRig) and post-exploitation tooling (Cobalt Strike, Meterpreter, Sharpire/PowerShell Empire); the report details the exploitation method, configuration payloads, observed scripts, and IoCs (MD5s, URLs) and recommends patching vulnerable ActiveMQ instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.