HelloKitty Ransomware Exploiting Apache ActiveMQ Flaw
The recently disclosed Apache ActiveMQ remote code execution (RCE) flaw, CVE-2023-46604 is being exploited to spread ransomware binaries on target systems and demand a ransom from the victim organizations.
Based on the evidence and the ransom note, Rapid7 experts have linked the activity to the HelloKitty ransomware family, whose source code was made public on a forum in early October.
CVE-2023-46604 is a critical severity RCE with a CVSS v3 score of 10.0, exploiting the serialized class types in the OpenWireprotocol that enables attackers to execute arbitrary shell commands.
“The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath,” ShadowServer reports.
The compromised environments’ indications were present in both of the impacted customer environments, which were using outdated Apache ActiveMQ versions.
On October 25, 2023, Apache announced the issue and updated ActiveMQ. Details on vulnerabilities and proof-of-concept exploit code are both made publicly available.
In 2020, the ransomware program HelloKitty appeared and has since been used in other high-profile attacks.
In this case, the attacker attempts to use the Windows Installer (msiexec) to load remote binaries with the names M2.png and M4.png after successful exploitation.
The 32-bit.NET executable named dllloader, contained in both MSI files, loads a Base64-encoded payload called EncDLL. EncDLL acts similarly to ransomware, searching and ending a particular set of processes before starting the encryption process and appending the encrypted files with the “.locked” extension.
The issues have been addressed in 5.15.16, 5.16.7, 5.17.6, or 5.18.3 versions.
As soon as feasible, organizations should upgrade to an addressed version of ActiveMQ and examine their systems for signs of vulnerability.
Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Try a free trial to ensure 100% security.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…