logo

'DripDropper' Hackers Patch Their Own Exploit

ID: 5166eb50-89d9-52e1-98f8-b954cbadfb73

STIX ID: report--5166eb50-89d9-52e1-98f8-b954cbadfb73

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-08-19

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Red Canary observed an active campaign abusing the CVE-2023-46604 Apache ActiveMQ RCE to access vulnerable Linux servers, run reconnaissance, and selectively deploy remote access tools (Sliver), Cloudflare Tunnel access, and a new Dropbox-based loader dubbed “DripDropper.” The attackers established persistence, modified SSH settings to enable root logins, and then replaced the vulnerable ActiveMQ components with patched JARs to block other intruders and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.