Mauri Ransomware Threat Actors Exploiting Apache ActiveMQ Vulnerability (CVE-2023-46604)
Dec. 16, 2024, 2:33 p.m.
Description
Threat actors are exploiting the CVE-2023-46604 vulnerability in Apache ActiveMQ to attack Korean systems, particularly using Mauri ransomware. The vulnerability allows remote code execution on unpatched servers. Attackers use XML configuration files to add backdoor accounts, install remote access tools like Quasar RAT, and set up proxies using Frpc. The Mauri ransomware, based on open-source code, is found on the attacker's server with customized configurations. While primarily targeting cryptocurrency mining, some cases involve system control and potential data theft. System administrators are urged to patch vulnerable Apache ActiveMQ versions and implement security measures to prevent attacks.
Tags
Date
- Created: Dec. 16, 2024, 12:45 p.m.
- Published: Dec. 16, 2024, 12:45 p.m.
- Modified: Dec. 16, 2024, 2:33 p.m.
Additional Informations
- Korea, Democratic People's Republic of
- Korea, Republic of