Godzilla Web Shell Attacks Stomp on Critical Apache ActiveMQ Flaw
ID: dd397842-6ced-5924-bfda-c825960a7c60
STIX ID: report--dd397842-6ced-5924-bfda-c825960a7c60
Feed Name: Dark Reading
Threat Score
Researchers report active exploitation of a critical Apache ActiveMQ insecure-deserialization flaw (CVE-2023-46604, CVSS 10.0) that attackers are using to deploy an obfuscated Godzilla JSP web shell to execute commands, perform network discovery, run Mimikatz, and drop ransomware and other malware; Trustwave and Rapid7 analyzed incidents, ShadowServer counts ~3,400 internet-exposed vulnerable servers, and IoCs/Yara detections have been published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
