Apache ActiveMQ Flaw Exploited in New Godzilla Web Shell Attacks
ID: 5ef35e62-f4ce-5b68-966f-9b0e2bf06b71
STIX ID: report--5ef35e62-f4ce-5b68-966f-9b0e2bf06b71
Feed Name: The Hacker News
Security researchers report active exploitation of Apache ActiveMQ CVE-2023-46604 (CVSS 10.0) by multiple threat actors to deploy the Godzilla JSP web shell; the web shell is concealed within an unknown binary format to evade scanners, is compiled and executed by the Jetty/ActiveMQ JSP engine, and provides remote code execution, file management, and command execution capabilities — observed payloads include ransomware, rootkits, cryptocurrency miners, and DDoS botnets. Administrators are strongly advised to update ActiveMQ to the latest patched version immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
