logo

Apache ActiveMQ Flaw Exploited in New Godzilla Web Shell Attacks

ID: 5ef35e62-f4ce-5b68-966f-9b0e2bf06b71

STIX ID: report--5ef35e62-f4ce-5b68-966f-9b0e2bf06b71

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-01-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Security researchers report active exploitation of Apache ActiveMQ CVE-2023-46604 (CVSS 10.0) by multiple threat actors to deploy the Godzilla JSP web shell; the web shell is concealed within an unknown binary format to evade scanners, is compiled and executed by the Jetty/ActiveMQ JSP engine, and provides remote code execution, file management, and command execution capabilities — observed payloads include ransomware, rootkits, cryptocurrency miners, and DDoS botnets. Administrators are strongly advised to update ActiveMQ to the latest patched version immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.