logo

Godzilla Web Shell Attacks Stomp on Critical Apache ActiveMQ Flaw

ID: dd397842-6ced-5924-bfda-c825960a7c60

STIX ID: report--dd397842-6ced-5924-bfda-c825960a7c60

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-01-22

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers report active exploitation of a critical Apache ActiveMQ insecure-deserialization flaw (CVE-2023-46604, CVSS 10.0) that attackers are using to deploy an obfuscated Godzilla JSP web shell to execute commands, perform network discovery, run Mimikatz, and drop ransomware and other malware; Trustwave and Rapid7 analyzed incidents, ShadowServer counts ~3,400 internet-exposed vulnerable servers, and IoCs/Yara detections have been published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.