Alert: Exploitation of CVE-2026-34197 in Apache ActiveMQ
ID: ef83c28a-4989-51b6-a3c0-06b48af2c48c
STIX ID: report--ef83c28a-4989-51b6-a3c0-06b48af2c48c
Feed Name: TeamT5 Blog
TeamT5 reports active exploitation of the critical Apache ActiveMQ RCE CVE-2026-34197 by China-nexus APT SLIME88; actors abused the Jolokia API to fetch malicious XML and achieve remote code execution, deployed the SoxAgent RAT to convert Linux hosts into SOCKS5 relays (ORB network tracked as GOBLIN14), impacted IT and manufacturing entities across the US, South Korea, India and France, and the advisory provides logs, SHA-256 IOCs, and mitigation steps including applying ActiveMQ patches and securing Jolokia/default credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
