Apache ActiveMQ Exploit Led to LockBit Ransomware Deployment

· Original article ↗

Summary

A threat actor exploited an unpatched Apache ActiveMQ server twice using CVE-2023-46604, then used stolen credentials and RDP to deploy LockBit ransomware across the network.

Key points

  • The actor exploited internet-facing Apache ActiveMQ vulnerability CVE-2023-46604 for remote code execution, returning through the same unpatched server 18 days after the first intrusion.
  • A Metasploit stager enabled SYSTEM-level access, LSASS memory access, and lateral movement using remote services; Microsoft Defender blocked some activity on protected hosts.
  • Credentials extracted during the first intrusion enabled the actor to regain access and move laterally, including to domain controllers, backup servers, and file servers.
  • During the second intrusion, the actor enabled RDP, installed AnyDesk, and used RDP sessions to execute ransomware across multiple hosts.
  • The ransomware matched LockBit signatures; investigators assessed it was built with the leaked LockBit builder, citing a modified ransom note and use of Session messaging.
  • The reported time from initial access to ransomware deployment was 419 hours; if the first intrusion had gone undetected, the second phase left less than 90 minutes before encryption.

Article Details

Attack Vectors
  • Exploitation of CVE-2023-46604 on an internet-facing Apache ActiveMQ server through a crafted OpenWire Exception Response referencing a malicious Java Spring bean configuration XML file.
  • Remote service execution using compromised domain administrator credentials and, during the second intrusion, a privileged service account assessed to have been recovered from LSASS during the first intrusion.
  • RDP sessions using compromised credentials to copy and interactively execute ransomware across servers.
  • Installation of AnyDesk on the initially compromised host to provide remote access.
Defensive Notes
  • Eviction without patching the exposed server allowed the attacker to exploit the same vulnerability again 18 days after initial access.
  • Active Microsoft Defender installations detected and blocked remote service creation and PowerShell execution on some hosts.
  • Emerging Threats rules detected the vulnerable ActiveMQ instance, exploitation attempts, and successful exploitation.
  • Relevant telemetry included Sysmon process execution, file creation, network connections, and process-access events; Windows service-installation and event-log-clearing events; and AnyDesk ad_svc.trace logs.
  • The reported time from initial access to ransomware deployment was 419 hours. After the attacker regained access, less than 90 minutes remained before ransomware execution.
  • Some network logs from the first exploitation were missing, limiting direct comparison of the two exploitation events.

Indicators of compromise

TypeIndicatorContext
IPV4166[.]62[.]100[.]52AnyDesk trace logs record an attacker login from this address on port 6761.
IPV4166[.]62[.]100[.]62The Command and Control section reports Metasploit stager communication to this address on port 2460.
SHA256722fff8f38197d1449df500ae31a95bb34a6ddaba56834b13eaaff2b0f9f1c8bHash of advanced_ip_scanner.exe, listed as an intrusion artifact associated with attacker network enumeration.
SHA25687bfb05057f215659cc801750118900145f8a22fa93ac4c6e1bfd81aa98b0a55Listed intrusion artifact netscan.exe; the attacker deployed Advanced IP Scanner disguised as SoftPerfect Network Scanner.
SHA2568ceee89550c521ba43f59d24ba53a22a3b69ead0fce118508d0a87a383d6a7b6Hash of lb3.exe, a LockBit ransomware executable deployed through RDP sessions.
SHA256c8646cfb574ff2c6f183c3c3951bf6b2c6cf16ff8a5e949a118be27f15962faeHash of lb3_pass.exe, a LockBit ransomware executable deployed with path and password flags.
SHA256d9c888bde81f19f3dc4f050d184ffa6470f1a93a2b3b10b3cc2d246574f56841Hash of rdp.bat, assessed to contain commands enabling RDP access and modifying firewall configuration.

MITRE ATT&CK

T1003.001 · LSASS MemoryMalicious processes accessed LSASS memory on multiple hosts during both intrusions to obtain credentials.T1021.001 · Remote Desktop ProtocolRDP sessions accessed backup, file, and other servers to transfer and interactively execute LockBit ransomware.T1021.002 · SMB/Windows Admin SharesCompromised accounts were used for SMB-associated lateral movement and remote service execution across hosts.T1027 · Obfuscated Files or InformationThe remote-execution PowerShell payload used string concatenation, substitutions, Base64 encoding, and gzip compression.T1036.005 · Match Legitimate Resource Name or LocationAdvanced IP Scanner was presented as SoftPerfect Network Scanner.T1046 · Network Service DiscoveryAdvanced IP Scanner enumerated the local network; earlier SMB traffic spikes were assessed as likely network scanning.T1055 · Process InjectionThe attacker used an injected Winlogon process to drop the RDP batch file and ransomware executables; LSASS-access call traces also indicated injected code.T1059.001 · PowerShellRemote services executed obfuscated PowerShell that allocated memory and launched decoded shellcode.T1059.003 · Windows Command ShellCMD executed the named-pipe command used during privilege escalation and commands configuring RDP access.T1069.002 · Domain GroupsThe attacker queried the domain administrator group during the second intrusion after earlier malformed discovery commands.T1070.001 · Clear Windows Event LogsThe attacker cleared System, Application, and Security event logs on the initially compromised host.T1070.004 · File DeletionThe attacker removed rdp.bat approximately six minutes after executing the RDP configuration commands.T1078.002 · Domain AccountsThe attacker used a domain administrator account and later a privileged service account for lateral movement.T1105 · Ingress Tool TransferCertUtil downloaded a Metasploit stager; additional executables and ransomware were subsequently transferred into the environment.T1134.001 · Token Impersonation/TheftMeterpreter getsystem activity created a service executing a named-pipe command and obtained SYSTEM privileges.T1140 · Deobfuscate/Decode Files or InformationPowerShell decoded the embedded Base64 shellcode before copying it into executable memory.T1190 · Exploit Public-Facing ApplicationThe attacker twice exploited CVE-2023-46604 on the exposed Apache ActiveMQ server to execute commands.T1219 · Remote Access ToolsThe attacker installed AnyDesk and logged into it from infrastructure also linked to exploitation and Metasploit C2.T1486 · Data Encrypted for ImpactLockBit executables encrypted systems across the environment and wrote ransom notes.T1491.001 · Internal DefacementThe ransomware changed desktop backgrounds to notify users of the ransom.T1543.003 · Windows ServiceAnyDesk installation created an AutoStart service on the initially compromised host.T1562.001 · Disable or Modify ToolsSystemSettingsAdminFlows.exe was used to disable Windows Defender settings on the Exchange server.T1562.004 · Disable or Modify System FirewallCommands modified the host firewall to permit RDP traffic.T1569.002 · Service ExecutionThe attacker executed Metasploit payloads through remote services during both rounds of intrusion.

CVE

People

Malware

Products

Tools

Related Articles