Cybersecurity researchers are warning of a suspected exploitation of a critical security flaw by the “Hello Kitty” Ransomware recently disclosed in the open-source Apache ActiveMQ messaging service

In both cases, the adversary attempted to deploy ransomware binaries on target systems in order to force victim organizations to pay ransom, the revelation came from cybersecurity firm Rapid7 in a report published Wednesday.
Based on the ransom note and available evidence, we attribute the activity to the ransomware . Its source code was leaked on a forum in early October.
The attacks are reported to exploit CVE-2023-46604, a remote code execution vulnerability in Apache ActiveMQ, which allows a malicious actor to execute arbitrary commands in the system shell.
It is worth noting that the vulnerability carries a CVSS score of 10.0, indicating maximum severity. It has been addressed in ActiveMQ versions 5.15.16, 5.16.7, 5.17.6 or 5.18.3 released late last month.
The vulnerability affects the following versions –
Apache ActiveMQ 5.18.0 before 5.18.3
Apache ActiveMQ 5.17.0 before 5.17.6
Apache ActiveMQ 5.16.0 before 5.16.7
Apache ActiveMQ before 5.15.16
Apache ActiveMQ Legacy OpenWire Module 5.18.0 before 5.18.3
Apache ActiveMQ Legacy OpenWire Module 5.17.0 before 5.17.6
Apache ActiveMQ Legacy OpenWire Module 5.16.0 before 5.16.7
Apache ActiveMQ Legacy OpenWire Module 5.8.0 before 5.15.16
Following the discovery of the flaws, a proof-of-concept (PoC) exploit code and additional technical specifications. According to Rapid7, the behavior observed on the two victim networks is similar to that expected from the CVE-2023-46604 exploit.
See more: Over 40 countries to sign to stop paying ransoms to ransomware gangs
After successful exploitation, the adversary attempts to remotely load binary files named M2.png and M4.png, using the Windows installer (msiexec).
Both MSI files contain a 32-bit .NET executable named dllloader. This file, in turn, loads a Base64-encoded payload called EncDLL. EncDLL works similarly to the “Hello Kitty” Ransomware, detecting and terminating a specific set of processes before the encryption and appending the files with the “.locked” extension.
The Shadowserver Foundation announced that it has identified 3,326 Internet-accessible instances of ActiveMQ exposed to CVE-2023-46604 as of November 1, 2023. Most of the vulnerable servers are located in China, the United States, Germany, South Korea, and India.

Considering the active exploitation of the vulnerability, we recommend that users update to the latest version of ActiveMQ as soon as possible and scan their networks for evidence of compromise.
Source: thehackernews.com
