Case of ActiveMQ Vulnerability Exploitation to Install Sharpire (Kinsing)
ID: b2c36655-aab5-5b9a-936c-5e49004f8287
STIX ID: report--b2c36655-aab5-5b9a-936c-5e49004f8287
Feed Name: ASEC
Threat Score
Kinsing (H2Miner) actors are actively exploiting Apache ActiveMQ CVE-2023-46604 to deploy downloaders, coinminers (XMRig) and post-exploitation tooling (Cobalt Strike, Meterpreter, Sharpire/PowerShell Empire); the report details the exploitation method, configuration payloads, observed scripts, and IoCs (MD5s, URLs) and recommends patching vulnerable ActiveMQ instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
