RansomwareThe DFIR Report·6 months ago
Apache ActiveMQ Exploit Leads to LockBit Ransomware
A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server in mid-February 2024 to achieve remote code execution using a Java Spring class, ultimately leading to LockBit ransomware deployment. The DFIR Report provides a detailed analysis of this intrusion chain, including insights into the attacker's techniques and methodology.