Thursday, September 24, 2026

Threat Actors Exploit Apache ActiveMQ Vulnerability to Gain RDP Access, Deploy LockBit Ransomware

Threat actors recently abused a critical Apache ActiveMQ vulnerability to gain deep access to a Windows environment, eventually deploying LockBit ransomware over RDP.

The attack shows how failing to patch CVE-2023-46604 can give adversaries repeat access and time to turn an initial foothold into full-domain impact.

The exploit loaded a malicious Java Spring bean configuration XML file, which instructed the server to use CertUtil to download a payload from a remote host.

The downloaded file was a Metasploit stager that connected back to the attacker’s command-and-control (C2) infrastructure, turning the ActiveMQ host into their beachhead.

In mid-February 2024, the attacker exploited CVE-2023-46604 on an internet-facing Apache ActiveMQ server, leveraging the Java OpenWire protocol vulnerability to achieve remote code execution.

Java Spring (Source : DFIR).
Java Spring (Source : DFIR).

Roughly 40 minutes after the initial exploit, the threat actor began post-exploitation activities through Metasploit, likely using Meterpreter.

Apache ActiveMQ Vulnerability

They ran GetSystem to escalate privileges to SYSTEM, then accessed the LSASS process memory to dump credentials from the beachhead server.

Execution (Source : DFIR).
Execution (Source : DFIR).

Sysmon event ID 1 showed the execution, with Java – the ActiveMQ server process – listed as the parent process.

Within the next 20 minutes, a spike in SMB traffic indicated network scanning, followed by lateral movement using a domain administrator account to execute Metasploit payloads as remote services on multiple hosts.

On several of these systems, LSASS memory was accessed again, and one server hosted a privileged service account tied to a line-of-business application, which later became crucial to the second-stage intrusion.​

During this first phase, the attackers also deployed AnyDesk for persistence and defense evasion, installing it as an AutoStart service and enabling RDP through firewall and registry changes via an rdp.bat script.

Reviewing the network traffic, we also saw the download of an executable file with the typical MZ header and the “This program cannot be run in DOS mode” string.


DOS mode (Source : DFIR).
DOS mode (Source : DFIR).

They cleared Windows System, Application, and Security event logs to hinder incident response, while active antivirus on some systems successfully blocked a subset of their Metasploit-based lateral movement.

On the second day, the attacker performed additional discovery with standard Windows utilities, albeit with syntax errors that suggested either unfamiliarity with Windows or a faulty playbook, before ultimately losing access to the environment.​

Command and Control (Source : DFIR).
Command and Control (Source : DFIR).

Eighteen days later, the same threat actor returned, exploiting Apache ActiveMQ server again using the same CVE-2023-46604 attack path and C2 infrastructure.

Mitigations

After repeating the GetSystem privilege escalation and LSASS credential theft on the beachhead, they quickly confirmed domain admin group membership and pivoted laterally using the previously harvested privileged service account.

They then used RDP to access key systems such as backup and file servers, ensuring RDP was enabled and dropping AnyDesk, network scanning tools, and two LockBit payloads (LB3_pass.exe and LB3.exe) staged under C:\Intel and user Downloads directories.


Lockbit Black ransomware execution (Source : DFIR).
Lockbit Black ransomware execution (Source : DFIR).

From there, the attacker executed LockBit ransomware interactively over RDP sessions across the environment for roughly four hours, using specific path and password flags on critical servers and leveraging a PsExec-style spreader option on others.

The ransomware binaries matched LockBit signatures but appeared to be generated with the leaked LockBit Black builder, as the ransom note diverged from standard LockBit guidance and instead instructed victims to communicate solely via the Session private messaging application rather than official LockBit infrastructure.

Overall time to ransomware was about 419 hours (19 days) from initial access, but once the actor re-entered the network on day 18, defenders had less than 90 minutes before widespread encryption began.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication

A highly severe vulnerability in Roundcube Webmail is being...

Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks

Check Point has warned customers about the active exploitation...

New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network

AvisLoader, a newly observed Windows malware loader designed to...

Microsoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks

An Integrated Security Operations Center (ISOC) in Microsoft Defender,...

RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials

A newly uncovered Android banking trojan dubbed RemControl is...

cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data

cPanel has released patches for CVE-2026-68490, a vulnerability related...

New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group

A newly identified ransomware operation tracked as Galago has...

Related Articles

Recent News