logo

Muhstik Malware Targets Message Queuing Services Applications

ID: b01abe6c-da02-506a-a189-862253725ef2

STIX ID: report--b01abe6c-da02-506a-a189-862253725ef2

Feed Name: Aqua Security Blog

Threat Score
72/100

Date Published: 2024-06-04

Date Updated: 2026-04-26

...
...

Aqua Nautilus reports an active campaign where attackers exploited Apache RocketMQ RCE (CVE-2023-33246) to deploy Muhstik malware; the analysis covers exploitation steps, execution and persistence mechanisms, IRC-based C2, observed IOCs (IPs, domains, SHA256 hashes), MITRE mappings, and an estimated 5,216 vulnerable RocketMQ instances discovered via Shodan.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.