Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware
## Cybersecurity: Apache ActiveMQ Vulnerability Exploitation
Cybersecurity: Apache ActiveMQ Vulnerability Exploitation
A critical vulnerability identified as CVE-2023-46604 in Apache ActiveMQ has been exploited, leading to the deployment of LockBit ransomware across an enterprise network. This remote code execution flaw was used to gain unauthorized access to a Windows server, facilitating system encryption through Remote Desktop Protocol over a period of 19 days.
The initial attack occurred in mid-February 2024, when a threat actor dispatched a crafted OpenWire command to a publicly exposed Apache ActiveMQ server. This exploit triggered the server to load a remote Java Spring XML configuration file, directing the host to download a Metasploit stager via the Windows CertUtil utility.
Within 40 minutes of initial access, attackers escalated privileges to SYSTEM level and extracted credentials from LSASS process memory. Despite being evicted on the second day, the vulnerability remained unpatched, allowing re-entry 18 days later through the same CVE-2023-46604 exploit.
Upon return, the attackers used a stolen service account to create services and execute Metasploit payloads across domain controllers and servers. They disguised network scanning tools and moved ransomware executables to various systems, executing them through RDP sessions.
The initial attack occurred in mid-February 2024, when a threat actor dispatched a crafted OpenWire command to a publicly exposed Apache ActiveMQ server.
The total time from initial exploitation to full encryption was 419 hours. Ransom notes directed victims to a private messaging app, suggesting the attack was carried out independently using the leaked LockBit Black builder.
IP Address: 166.62.100[.]52 - C2 server and AnyDesk login source SHA-256: C8646CFB574FF2C6F183C3C3951BF6B2C6CF16FF8A5E949A118BE27F15962FAE - LB3_pass.exe, LockBit ransomware executable SHA-256: 8CEEE89550C521BA43F59D24BA53A22A3B69EAD0FCE118508D0A87A383D6A7B6 - LB3.exe, LockBit ransomware executable SHA-256: 87BFB05057F215659CC801750118900145F8A22FA93AC4C6E1BFD81AA98B0A55 - netscan.exe, Network scanner tool SHA-256: 722FFF8F38197D1449DF500AE31A95BB34A6DDABA56834B13EAAFF2B0F9F1C8B - advanced_ip_scanner.exe, IP scanner disguise SHA-256: D9C888BDE81F19F3DC4F050D184FFA6470F1A93A2B3B10B3CC2D246574F56841 - rdp.bat, RDP configuration batch file AnyDesk Client ID: 1148037084 - Attacker’s AnyDesk client identifier
Organizations should immediately patch Apache ActiveMQ to address CVE-2023-46604, enforce LSASS protection through Credential Guard, monitor for event log clearing activity, restrict unauthorized remote access tool installations, and reset all credentials following any suspected intrusion to prevent re-entry through stolen accounts.
Based on reporting by Cyber Security News.
