Apache ActiveMQ Exploit Led to LockBit Ransomware Deployment

Summary
A threat actor exploited an unpatched Apache ActiveMQ server twice using CVE-2023-46604, then used stolen credentials and RDP to deploy LockBit ransomware across the network.
Key points
- The actor exploited internet-facing Apache ActiveMQ vulnerability CVE-2023-46604 for remote code execution, returning through the same unpatched server 18 days after the first intrusion.
- A Metasploit stager enabled SYSTEM-level access, LSASS memory access, and lateral movement using remote services; Microsoft Defender blocked some activity on protected hosts.
- Credentials extracted during the first intrusion enabled the actor to regain access and move laterally, including to domain controllers, backup servers, and file servers.
- During the second intrusion, the actor enabled RDP, installed AnyDesk, and used RDP sessions to execute ransomware across multiple hosts.
- The ransomware matched LockBit signatures; investigators assessed it was built with the leaked LockBit builder, citing a modified ransom note and use of Session messaging.
- The reported time from initial access to ransomware deployment was 419 hours; if the first intrusion had gone undetected, the second phase left less than 90 minutes before encryption.
Article Details
- Attack Vectors
- Exploitation of CVE-2023-46604 on an internet-facing Apache ActiveMQ server through a crafted OpenWire Exception Response referencing a malicious Java Spring bean configuration XML file.
- Remote service execution using compromised domain administrator credentials and, during the second intrusion, a privileged service account assessed to have been recovered from LSASS during the first intrusion.
- RDP sessions using compromised credentials to copy and interactively execute ransomware across servers.
- Installation of AnyDesk on the initially compromised host to provide remote access.
- Defensive Notes
- Eviction without patching the exposed server allowed the attacker to exploit the same vulnerability again 18 days after initial access.
- Active Microsoft Defender installations detected and blocked remote service creation and PowerShell execution on some hosts.
- Emerging Threats rules detected the vulnerable ActiveMQ instance, exploitation attempts, and successful exploitation.
- Relevant telemetry included Sysmon process execution, file creation, network connections, and process-access events; Windows service-installation and event-log-clearing events; and AnyDesk ad_svc.trace logs.
- The reported time from initial access to ransomware deployment was 419 hours. After the attacker regained access, less than 90 minutes remained before ransomware execution.
- Some network logs from the first exploitation were missing, limiting direct comparison of the two exploitation events.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 166[.]62[.]100[.]52 | AnyDesk trace logs record an attacker login from this address on port 6761. |
| IPV4 | 166[.]62[.]100[.]62 | The Command and Control section reports Metasploit stager communication to this address on port 2460. |
| SHA256 | 722fff8f38197d1449df500ae31a95bb34a6ddaba56834b13eaaff2b0f9f1c8b | Hash of advanced_ip_scanner.exe, listed as an intrusion artifact associated with attacker network enumeration. |
| SHA256 | 87bfb05057f215659cc801750118900145f8a22fa93ac4c6e1bfd81aa98b0a55 | Listed intrusion artifact netscan.exe; the attacker deployed Advanced IP Scanner disguised as SoftPerfect Network Scanner. |
| SHA256 | 8ceee89550c521ba43f59d24ba53a22a3b69ead0fce118508d0a87a383d6a7b6 | Hash of lb3.exe, a LockBit ransomware executable deployed through RDP sessions. |
| SHA256 | c8646cfb574ff2c6f183c3c3951bf6b2c6cf16ff8a5e949a118be27f15962fae | Hash of lb3_pass.exe, a LockBit ransomware executable deployed with path and password flags. |
| SHA256 | d9c888bde81f19f3dc4f050d184ffa6470f1a93a2b3b10b3cc2d246574f56841 | Hash of rdp.bat, assessed to contain commands enabling RDP access and modifying firewall configuration. |
MITRE ATT&CK
T1003.001 · LSASS MemoryMalicious processes accessed LSASS memory on multiple hosts during both intrusions to obtain credentials.T1021.001 · Remote Desktop ProtocolRDP sessions accessed backup, file, and other servers to transfer and interactively execute LockBit ransomware.T1021.002 · SMB/Windows Admin SharesCompromised accounts were used for SMB-associated lateral movement and remote service execution across hosts.T1027 · Obfuscated Files or InformationThe remote-execution PowerShell payload used string concatenation, substitutions, Base64 encoding, and gzip compression.T1036.005 · Match Legitimate Resource Name or LocationAdvanced IP Scanner was presented as SoftPerfect Network Scanner.T1046 · Network Service DiscoveryAdvanced IP Scanner enumerated the local network; earlier SMB traffic spikes were assessed as likely network scanning.T1055 · Process InjectionThe attacker used an injected Winlogon process to drop the RDP batch file and ransomware executables; LSASS-access call traces also indicated injected code.T1059.001 · PowerShellRemote services executed obfuscated PowerShell that allocated memory and launched decoded shellcode.T1059.003 · Windows Command ShellCMD executed the named-pipe command used during privilege escalation and commands configuring RDP access.T1069.002 · Domain GroupsThe attacker queried the domain administrator group during the second intrusion after earlier malformed discovery commands.T1070.001 · Clear Windows Event LogsThe attacker cleared System, Application, and Security event logs on the initially compromised host.T1070.004 · File DeletionThe attacker removed rdp.bat approximately six minutes after executing the RDP configuration commands.T1078.002 · Domain AccountsThe attacker used a domain administrator account and later a privileged service account for lateral movement.T1105 · Ingress Tool TransferCertUtil downloaded a Metasploit stager; additional executables and ransomware were subsequently transferred into the environment.T1134.001 · Token Impersonation/TheftMeterpreter getsystem activity created a service executing a named-pipe command and obtained SYSTEM privileges.T1140 · Deobfuscate/Decode Files or InformationPowerShell decoded the embedded Base64 shellcode before copying it into executable memory.T1190 · Exploit Public-Facing ApplicationThe attacker twice exploited CVE-2023-46604 on the exposed Apache ActiveMQ server to execute commands.T1219 · Remote Access ToolsThe attacker installed AnyDesk and logged into it from infrastructure also linked to exploitation and Metasploit C2.T1486 · Data Encrypted for ImpactLockBit executables encrypted systems across the environment and wrote ransom notes.T1491.001 · Internal DefacementThe ransomware changed desktop backgrounds to notify users of the ransom.T1543.003 · Windows ServiceAnyDesk installation created an AutoStart service on the initially compromised host.T1562.001 · Disable or Modify ToolsSystemSettingsAdminFlows.exe was used to disable Windows Defender settings on the Exchange server.T1562.004 · Disable or Modify System FirewallCommands modified the host firewall to permit RDP traffic.T1569.002 · Service ExecutionThe attacker executed Metasploit payloads through remote services during both rounds of intrusion.
CVE
People
Malware
Products
Apache ActiveMQA threat actor exploited CVE-2023-46604 on an internet-facing Apache ActiveMQ server.ExchangeOn the Exchange email server, the threat actor used a legitimate Windows executable, SystemSettingsAdminFlows.exe, which allows users to customize or configure the system settings to user’s preference.Microsoft DefenderOn some hosts, Microsoft Defender antivirus was active.Microsoft WindowsThe malicious XML contained a command that downloaded a payload from a remote server using the Windows CertUtil utility.Windows DefenderThis LOLBIN was used to disable Windows Defender settings on the server.
Tools
Advanced IP ScannerThese included a renamed Advanced IP Scanner binary and two LockBit ransomware files.AnyDeskThey dropped a batch file and AnyDesk installer on the beachhead host.CyberChefCyberchef recipe to perform the deobfuscationLockBit Black builderBased on the ransom note dropped after execution, we assess that the ransomware was created using the leaked LockBit Black builder.MetasploitAfter compromising the server, the threat actor used Metasploit, possibly along with Meterpreter, to perform post-exploitation activities.MeterpreterAfter compromising the server, the threat actor used Metasploit, possibly along with Meterpreter, to perform post-exploitation activities.speakeasyUsing YARA and speakeasy allowed us to confirm it as a Metasploit executable that communicated with 166.62.100[.]52.YARAUsing YARA and speakeasy allowed us to confirm it as a Metasploit executable that communicated with 166.62.100[.]52.