Tag: Apache ActiveMQ Vulnerability

GoTitan Botnet Spotted Exploiting Recent Apache ActiveMQ Vulnerability
News

GoTitan Botnet Spotted Exploiting Recent Apache ActiveMQ Vulnerability

Threat actors are actively using the recently discovered critical security flaw affecting Apache ActiveMQ to spread a new Go-based botnet called GoTitan and a.NET application called PrCtrl Rat, which has the ability to remotely commandeer the compromised hosts. The attacks take advantage of a remote code execution bug (CVE-2023-46604, CVSS score: 10.0) that has recently been turned into a weapon by a number of hacker groups, including the Lazarus Group. Threat actors have been seen to drop next-stage payloads from a remote server after a successful breach. One of these payloads is GoTitan, a botnet that is intended read more GoTitan Botnet Spotted Exploiting Recent Apache ActiveMQ Vulnerability. Get up to date on the latest cybersecurity news and enhance your knowledge of cyberse...
HelloKitty Ransomware Group Exploiting Apache ActiveMQ Vulnerability
News

HelloKitty Ransomware Group Exploiting Apache ActiveMQ Vulnerability

Researchers studying cybersecurity are alerting users to the possibility of remote code execution due to the possible exploitation of a recently discovered, serious security vulnerability in the Apache ActiveMQ open-source message broker service. The cybersecurity company Rapid7 revealed in a study released on Wednesday that the adversary attempted to install ransomware binaries on target computers in both cases with the intention of holding the victim organization ransom. We identify the activity as coming from the HelloKitty ransomware family, whose source code was made public on a forum in early October, based on the ransom message and the information that is now accessible. According to reports, the incursions entail the use of Apache read more HelloKitty Ransomware Group Exp...