logo

Beware of the Messengers, Exploiting ActiveMQ Vulnerability

ID: 238b60cc-a5a0-5d2e-bf5d-db9d4bc8f4bb

STIX ID: report--238b60cc-a5a0-5d2e-bf5d-db9d4bc8f4bb

Feed Name: Cybereason Blog

Threat Score
78/100

Date Published: 2024-03-13

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason reports that attackers have been actively exploiting Apache ActiveMQ CVE-2023-46604 (unauthenticated RCE via insecure OpenWire deserialization) since at least October 11, 2023, to deploy a variety of malware—including Mirai botnet binaries, SparkRAT, HelloKitty ransomware, XMRig coinminers and ConnectBack backdoors—using wget/curl downloads, Base64-encoded scripts, and reverse shells; the report includes detailed IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.