'DripDropper' Hackers Patch Their Own Exploit
ID: 5166eb50-89d9-52e1-98f8-b954cbadfb73
STIX ID: report--5166eb50-89d9-52e1-98f8-b954cbadfb73
Feed Name: Dark Reading
Threat Score
Red Canary observed an active campaign abusing the CVE-2023-46604 Apache ActiveMQ RCE to access vulnerable Linux servers, run reconnaissance, and selectively deploy remote access tools (Sliver), Cloudflare Tunnel access, and a new Dropbox-based loader dubbed “DripDropper.” The attackers established persistence, modified SSH settings to enable root logins, and then replaced the vulnerable ActiveMQ components with patched JARs to block other intruders and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
