CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Apache ActiveMQ Exploit Leads to LockBit Ransomware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 577

As cited

Copy frozen at (site build).

ransomware

Apache ActiveMQ Exploit Leads to LockBit Ransomware

A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server in mid-February 2024 to achieve remote code execution using a Java Spring class, leading to LockBit ransomware deployment. The intrusion demonstrates how unpatched critical vulnerabilities in internet-facing services remain an effective attack vector for ransomware operators.

Why it matters: Organizations running Apache ActiveMQ need to verify patches for CVE-2023-46604 are deployed; exposed instances face immediate ransomware risk from active threat actors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Apache ActiveMQ Exploit Leads to LockBit Ransomware

A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server in mid-February 2024 to achieve remote code execution using a Java Spring class, leading to LockBit ransomware deployment. The intrusion demonstrates how unpatched critical vulnerabilities in internet-facing services remain an effective attack vector for ransomware operators.

Why it matters: Organizations running Apache ActiveMQ need to verify patches for CVE-2023-46604 are deployed; exposed instances face immediate ransomware risk from active threat actors.

VendorsAppleOracle
Actorslockbit
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary