Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware

## Cybersecurity: Apache ActiveMQ Vulnerability Exploitation

Cybersecurity: Apache ActiveMQ Vulnerability Exploitation

A critical vulnerability identified as CVE-2023-46604 in Apache ActiveMQ has been exploited, leading to the deployment of LockBit ransomware across an enterprise network. This remote code execution flaw was used to gain unauthorized access to a Windows server, facilitating system encryption through Remote Desktop Protocol over a period of 19 days.

The initial attack occurred in mid-February 2024, when a threat actor dispatched a crafted OpenWire command to a publicly exposed Apache ActiveMQ server. This exploit triggered the server to load a remote Java Spring XML configuration file, directing the host to download a Metasploit stager via the Windows CertUtil utility.

Within 40 minutes of initial access, attackers escalated privileges to SYSTEM level and extracted credentials from LSASS process memory. Despite being evicted on the second day, the vulnerability remained unpatched, allowing re-entry 18 days later through the same CVE-2023-46604 exploit.

Upon return, the attackers used a stolen service account to create services and execute Metasploit payloads across domain controllers and servers. They disguised network scanning tools and moved ransomware executables to various systems, executing them through RDP sessions.

The initial attack occurred in mid-February 2024, when a threat actor dispatched a crafted OpenWire command to a publicly exposed Apache ActiveMQ server.
Aiden Sinclair · Thehackingpost

The total time from initial exploitation to full encryption was 419 hours. Ransom notes directed victims to a private messaging app, suggesting the attack was carried out independently using the leaked LockBit Black builder.

IP Address: 166.62.100[.]52 - C2 server and AnyDesk login source SHA-256: C8646CFB574FF2C6F183C3C3951BF6B2C6CF16FF8A5E949A118BE27F15962FAE - LB3_pass.exe, LockBit ransomware executable SHA-256: 8CEEE89550C521BA43F59D24BA53A22A3B69EAD0FCE118508D0A87A383D6A7B6 - LB3.exe, LockBit ransomware executable SHA-256: 87BFB05057F215659CC801750118900145F8A22FA93AC4C6E1BFD81AA98B0A55 - netscan.exe, Network scanner tool SHA-256: 722FFF8F38197D1449DF500AE31A95BB34A6DDABA56834B13EAAFF2B0F9F1C8B - advanced_ip_scanner.exe, IP scanner disguise SHA-256: D9C888BDE81F19F3DC4F050D184FFA6470F1A93A2B3B10B3CC2D246574F56841 - rdp.bat, RDP configuration batch file AnyDesk Client ID: 1148037084 - Attacker’s AnyDesk client identifier

Advertisement

Organizations should immediately patch Apache ActiveMQ to address CVE-2023-46604, enforce LSASS protection through Credential Guard, monitor for event log clearing activity, restrict unauthorized remote access tool installations, and reset all credentials following any suspected intrusion to prevent re-entry through stolen accounts.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories