216.73.217.22

Malware Targets Message Queuing Services Applications

· Published 06/06/2024 18:44 · Modified 06/06/2024 19:09

Export JSON

Essential information

Published
06/06/2024 18:44
Modified
06/06/2024 19:09
Tags
2024-06-06 CVE-2023-33246 apache cryptocurrency evasion irc lateral muhstik persistence rocketmq vulnerability
Related entities
1 vulnerabilities (cve), 21 observables, 13 techniques (mitre), 1 malware

Description

The report describes a recent campaign targeting platforms, where attackers exploited a known () to gain remote code execution on the systems. They then downloaded and executed the malware, which provides , evades detection, performs movement, and communicates through an command-and-control server. The malware can be used for mining and launching distributed denial-of-service attacks. The report also analyzes the prevalence of vulnerable instances worldwide and provides recommendations for securing cloud-native environments.

External references