Tag: DripDropper Malware

Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems
News

Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems

Threat actors are gaining permanent access to cloud Linux servers and distributing malware known as DripDropper by taking advantage of a security hole in Apache ActiveMQ that has existed for almost two years. However, in a surprising turn of events, Red Canary reported to The Hacker News that the unidentified attackers had been seen patching the exploited vulnerability after gaining initial access in order to avoid notice and stop additional exploitation by other adversaries. According to researchers Christina Johns, Chris Brook, and Tyler Edmonds, follow-on adversary command-and-control (C2) techniques differed depending on the endpoint and included Sliver and Cloudflare Tunnels to sustain long-term covert command and control. The attacks take advantage of a remote code executio...