Beware of the Messengers, Exploiting ActiveMQ Vulnerability
ID: 238b60cc-a5a0-5d2e-bf5d-db9d4bc8f4bb
STIX ID: report--238b60cc-a5a0-5d2e-bf5d-db9d4bc8f4bb
Feed Name: Cybereason Blog
Threat Score
Cybereason reports that attackers have been actively exploiting Apache ActiveMQ CVE-2023-46604 (unauthenticated RCE via insecure OpenWire deserialization) since at least October 11, 2023, to deploy a variety of malware—including Mirai botnet binaries, SparkRAT, HelloKitty ransomware, XMRig coinminers and ConnectBack backdoors—using wget/curl downloads, Base64-encoded scripts, and reverse shells; the report includes detailed IoCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
