logo

Muhstik Botnet Exploiting Apache RocketMQ Flaw to Expand DDoS Attacks

ID: 67d408e6-1c97-5978-8eb0-5c3b265e6597

STIX ID: report--67d408e6-1c97-5978-8eb0-5c3b265e6597

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-06-06

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Muhstik botnet operators are actively exploiting a critical Apache RocketMQ RCE (CVE-2023-33246, CVSS 9.8) to deploy a Linux/IoT-focused malware (binary named "pty3") that establishes persistence, performs lateral movement via SSH, phones home over IRC, and is used for DDoS and cryptomining; over 5,200 RocketMQ instances remain exposed. The report also highlights attackers targeting poorly secured MS-SQL servers via brute-force, urging patching and stronger passwords.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.