Apache ActiveMQ Ransomware Attack
Ransomware attackers actively targeting Apache ActiveMQ flaw
https://activemq.apache.org/news/cve-2023-46604
Ransomware attackers are targeting servers running outdated and vulnerable versions of Apache ActiveMQ by exploiting a recently fixed vulnerability (CVE-2023-46604).
Background
Apache ActiveMQ is a popular open source message broker – a program that translates a messages from one messaging protocol to another, allowing communication between diverse services and systems. ActiveMQ supports a variety of protocols, including OpenWire, MQTT (messaging protocol for IoT), AMQP (protocol for business messaging and IoT device management), REST, STOMP, etc. This vulnerability CVE2023-46604, may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol. Technical details and proof-of-concept (PoC) code for CVE-2023-46604 are publicly available and could be leveraged by other threat groups looking to exploit the vulnerability. As of 6th Oct, 2023, according to shadow server there are more than 3000+ servers accessible for the internet which are vulnerable to CVE-2023-46604.
Announced
Oct, 2023: Apache released an advisory: Oct 25, 2023: Apache released the patch fix for CVE-2023-46604 Nov 02, 2023: CISA added CVE-2023-46604 to its known exploited list, KEV Catalog.
Latest Developments
FortiGuard Labs recommends applying available patches for Apache ActiveMQ as soon as possible if not already done. Apache also has information on improving the security of ActiveMQ implementations.
arrow_icon
PROTECT

Countermeasures across the security fabric for protecting assets, data and network from cybersecurity events:

Reconnaissance

Lure
Decoy VM
Weaponization

Delivery

AV

Detects and blocks malware related to Apache ActiveMQ Ransomware Attack

DB 91.08565
DB 91.08565
DB 91.08565
DB 91.08565
DB 91.08565
DB 91.08565
DB 91.08565
DB 91.08565
Vulnerability

Detects and blocks attack targeting Apache ActiveMQ servers (CVE-2023-46604)

DB 1.569
AV (Pre-filter)

Detects and blocks malware related to Apache ActiveMQ Ransomware Attack

DB 91.08565
DB 91.08565
DB 91.08565
Behavior Detection

Behavior Dectection Engine detects HelloKitty ransomware malware as "High risk" and blocks other 0-day threats

Exploitation

IPS

Detects and blocks attack targeting Apache ActiveMQ servers (CVE-2023-46604)

DB 26.673
DB 26.673
DB 26.673
DB 26.673
DB 26.673
Installation
C2
Action
arrow_icon
DETECT

Find and correlate important information to identify an outbreak, the following updates are available to raise alert and generate reports:

Outbreak Detection

DB 1.00016
DB 2.00025
DB 601
Threat Hunting
arrow_icon
RESPOND

Develop containment techniques to mitigate impacts of security events:

Automated Response

Services that can automaticlly respond to this outbreak.

Assisted Response Services

Experts to assist you with analysis, containment and response activities.

arrow_icon
RECOVER

Improve security posture and processes by implementing security awareness and training, in preparation for (and recovery from) security incidents:

NOC/SOC Training

Train your network and security professionals and optimize your incident response to stay on top of the cyberattacks.

End-User Training

Raise security awareness to your employees that are continuously being targetted by phishing, drive-by download and other forms of cyberattacks.

arrow_icon
IDENTIFY

Identify processes and assets that need protection:

Attack Surface Hardening

Check Security Fabric devices to build actionable configuration recommendations and key indicators.

Vulnerability Management

Reduce the attack surface on software vulnerabilities via systematic and automated patching.

Business Reputation

Know attackers next move to protect against your business branding.