Today > 2 Critical | 11 High | 12 Medium vulnerabilities   -   You can now download lists of IOCs here!

Mauri Ransomware Threat Actors Exploiting Apache ActiveMQ Vulnerability (CVE-2023-46604)

Dec. 16, 2024, 2:33 p.m.

Description

Threat actors are exploiting the CVE-2023-46604 vulnerability in Apache ActiveMQ to attack Korean systems, particularly using Mauri ransomware. The vulnerability allows remote code execution on unpatched servers. Attackers use XML configuration files to add backdoor accounts, install remote access tools like Quasar RAT, and set up proxies using Frpc. The Mauri ransomware, based on open-source code, is found on the attacker's server with customized configurations. While primarily targeting cryptocurrency mining, some cases involve system control and potential data theft. System administrators are urged to patch vulnerable Apache ActiveMQ versions and implement security measures to prevent attacks.

Date

Published: Dec. 16, 2024, 12:45 p.m.

Created: Dec. 16, 2024, 12:45 p.m.

Modified: Dec. 16, 2024, 2:33 p.m.

Attack Patterns

Mauri Ransomware

Quasar RAT

CoinMiner

T1569.002

T1021.001

T1573

T1486

T1547

T1105

T1566

T1190

T1133

T1090

T1078

Additional Informations

Korea, Democratic People's Republic of

Korea, Republic of