Mauri Ransomware Threat Actors Exploiting Apache ActiveMQ Vulnerability (CVE-2023-46604)
Dec. 16, 2024, 2:33 p.m.
Tags
External References
Description
Threat actors are exploiting the CVE-2023-46604 vulnerability in Apache ActiveMQ to attack Korean systems, particularly using Mauri ransomware. The vulnerability allows remote code execution on unpatched servers. Attackers use XML configuration files to add backdoor accounts, install remote access tools like Quasar RAT, and set up proxies using Frpc. The Mauri ransomware, based on open-source code, is found on the attacker's server with customized configurations. While primarily targeting cryptocurrency mining, some cases involve system control and potential data theft. System administrators are urged to patch vulnerable Apache ActiveMQ versions and implement security measures to prevent attacks.
Date
Published: Dec. 16, 2024, 12:45 p.m.
Created: Dec. 16, 2024, 12:45 p.m.
Modified: Dec. 16, 2024, 2:33 p.m.
Attack Patterns
Mauri Ransomware
Quasar RAT
CoinMiner
T1569.002
T1021.001
T1573
T1486
T1547
T1105
T1566
T1190
T1133
T1090
T1078
Additional Informations
Korea, Democratic People's Republic of
Korea, Republic of