Muhstik Malware Targets Message Queuing Services Applications
ID: b01abe6c-da02-506a-a189-862253725ef2
STIX ID: report--b01abe6c-da02-506a-a189-862253725ef2
Feed Name: Aqua Security Blog
Threat Score
Aqua Nautilus reports an active campaign where attackers exploited Apache RocketMQ RCE (CVE-2023-33246) to deploy Muhstik malware; the analysis covers exploitation steps, execution and persistence mechanisms, IRC-based C2, observed IOCs (IPs, domains, SHA256 hashes), MITRE mappings, and an estimated 5,216 vulnerable RocketMQ instances discovered via Shodan.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
