HomeSecurity"Hello Kitty" Ransomware: Exploited Vulnerability in Open Source Apache ActiveMQ

“Hello Kitty” Ransomware: Exploited Vulnerability in Open Source Apache ActiveMQ

Cybersecurity researchers are warning of a suspected exploitation of a critical security flaw by the “Hello Kitty” Ransomware recently disclosed in the open-source Apache ActiveMQ messaging service

Apache ActiveMQ open source

In both cases, the adversary attempted to deploy ransomware binaries on target systems in order to force victim organizations to pay ransom, the revelation came from cybersecurity firm Rapid7 in a report published Wednesday.

Based on the ransom note and available evidence, we attribute the activity to the ransomware . Its source code was leaked on a forum in early October.

The attacks are reported to exploit CVE-2023-46604, a remote code execution vulnerability in Apache ActiveMQ, which allows a malicious actor to execute arbitrary commands in the system shell.

It is worth noting that the vulnerability carries a CVSS score of 10.0, indicating maximum severity. It has been addressed in ActiveMQ versions 5.15.16, 5.16.7, 5.17.6 or 5.18.3 released late last month.

The vulnerability affects the following versions –

Apache ActiveMQ 5.18.0 before 5.18.3

Apache ActiveMQ 5.17.0 before 5.17.6

Apache ActiveMQ 5.16.0 before 5.16.7

Apache ActiveMQ before 5.15.16

Apache ActiveMQ Legacy OpenWire Module 5.18.0 before 5.18.3

Apache ActiveMQ Legacy OpenWire Module 5.17.0 before 5.17.6

Apache ActiveMQ Legacy OpenWire Module 5.16.0 before 5.16.7

Apache ActiveMQ Legacy OpenWire Module 5.8.0 before 5.15.16

Following the discovery of the flaws, a proof-of-concept (PoC) exploit code and additional technical specifications. According to Rapid7, the behavior observed on the two victim networks is similar to that expected from the CVE-2023-46604 exploit.

See more: Over 40 countries to sign to stop paying ransoms to ransomware gangs

After successful exploitation, the adversary attempts to remotely load binary files named M2.png and M4.png, using the Windows installer (msiexec).

Both MSI files contain a 32-bit .NET executable named dllloader. This file, in turn, loads a Base64-encoded payload called EncDLL. EncDLL works similarly to the “Hello Kitty” Ransomware, detecting and terminating a specific set of processes before the encryption and appending the files with the “.locked” extension.

The Shadowserver Foundation announced that it has identified 3,326 Internet-accessible instances of ActiveMQ exposed to CVE-2023-46604 as of November 1, 2023. Most of the vulnerable servers are located in China, the United States, Germany, South Korea, and India.

"Hello Kitty" Ransomware

Considering the active exploitation of the vulnerability, we recommend that users update to the latest version of ActiveMQ as soon as possible and scan their networks for evidence of compromise.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS