ActiveMQ CVE-2023-46604 exploited by Kinsing intrusion set
ID: c374ebde-16c9-5f86-968c-09538cb5e56c
STIX ID: report--c374ebde-16c9-5f86-968c-09538cb5e56c
Feed Name: Sekoia.com
**Executive summary:** Sekoia TDR observed Kinsing rapidly exploiting ActiveMQ CVE-2023-46604 in the wild to deliver a Go-based Kinsing payload that installs a rootkit, removes competitors, establishes persistence, spreads via SSH, and deploys an XMRig cryptominer; the report includes malware technical details (hash, compilation, C2/decryption methods), infrastructure and IPs, Monero wallet tracking and earnings, IoCs, and mitigation advice to patch ActiveMQ or restrict OpenWire exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
