The DreamBus malware exploits a vulnerability in RocketMQ to infect servers.
A new version of the DreamBus malware exploits a high-severity remote code execution vulnerability in RocketMQ servers to infect devices.
The vulnerability being exploited, with identifier CVE-2023-33246, is a permission verification issue that affects RocketMQ version 5.1.0 and earlier, allowing attackers to execute remote commands under certain conditions.
Recent DreamBus attacks exploiting this vulnerability were identified by researchers at Juniper Threat Labs, who reported a spike in activity in June 2023.

Exploiting unpatched server
Juniper Threat Labs reports that it saw the first DreamBus attacks exploiting CVE-2023-33246 in early June 2023, targeting RocketMQ's default port 10911 and seven other ports.
The attackers used the open-source identification tool 'interactsh' to determine which software version is running on web servers exposed to the internet and extract potential exploitable vulnerabilities.
Researchers also spotted the threat actor downloading a malicious bash script named “reketed” from a Tor proxy service, which evaded detection by AV engines on VirusTotal.
This obfuscated script is a downloader and installer for the main DreamBus module (ELF file), which was downloaded from a Tor site. The file is deleted after execution to minimize the chances of detection.
The main DreamBus module, which also goes unnoticed by all VirusTotal AV detections thanks to custom UPX compression, includes several base64-encrypted scripts that perform various functions, including downloading additional files for the malware.
The main module decodes these strings to perform tasks such as signaling its online status to the C2, downloading the open source Monero miner XMRig, executing additional bash scripts, or downloading a new version of malware.
DreamBus ensures its activation on infected systems by creating a system service and a scheduled cron job, both of which run hourly.
The malware also includes propagation mechanisms using tools such as ansible, knife, salt, and pssh, as well as a scanner module that checks external and internalIP address to index vulnerabilities.
The main goal of the ongoing DreamBus attack appears to be mining the cryptocurrency Monero, although its modularity could allow attackers to easily expand its capabilities in a future update.
Considering that RocketMQ servers are used in communications, attackers could theoretically decide to intercept sensitive chat data handled by compromised devices, which could have greater potential for profit than the cryptocurrency miner on hijacked resources.
To stop the latest DreamBus attacks, RockerMQ administrators are advised to upgrade to version 5.1.1 or later.
Previous versions of the DreamBus malware are also known to target Redis, PostgreSQL, Hadoop YARN, Apache Spark, HashiCorp Consul, and SaltStack, so proper patch management across all software products is recommended to address this threat.
Information source: bleepingcomputer.com
