216.73.217.22

Apache ActiveMQ Exploit Leads to LockBit Ransomware

· Published 23/02/2026 22:38 · Modified 23/02/2026 23:21

Export JSON

Essential information

Published
23/02/2026 22:38
Modified
23/02/2026 23:21
Tags
2026-02-23 CVE-2023-46604 apache activemq credential-theft lateral movement lockbit metasploit ransomware rdp
Related entities
3 observables, 17 techniques (mitre)

Description

A threat actor exploited on an exposed server, gaining initial access and later returning after being evicted. The attacker used for post-exploitation activities, including privilege escalation, credential access, and . Upon regaining access, they swiftly deployed via using previously extracted credentials. The binary matched signatures but was likely crafted using the leaked builder, as evidenced by modified ransom notes and communication methods. The intrusion spanned 19 days from initial access to deployment, with less than 90 minutes between re-engagement and encryption during the second phase.

External references