Security News > 2023 > August > DreamBus malware exploits RocketMQ flaw to infect servers

DreamBus malware exploits RocketMQ flaw to infect servers
2023-08-29 19:17

A new version of the DreamBus botnet malware exploits a critical-severity remote code execution vulnerability in RocketMQ servers to infect devices.

The recent DreamBus attacks leveraging that flaw were spotted by researchers at the Juniper Threat Labs, who reported a spike in the activity in mid-June 2023.

The main DreamBus module, which also passes all VirusTotal AV scans undetected thanks to custom UPX packing, features several base64-encoded scripts that perform different functions, including downloading additional modules for the malware.

Earlier versions of the DreamBus malware are also known to target Redis, PostgreSQL, Hadoop YARN, Apache Spark, HashiCorp Consul, and SaltStack, so following good patch management across all software products is recommended to tackle this threat.

Gafgyt malware exploits five-years-old flaw in EoL Zyxel router.

New Zerobot malware has 21 exploits for BIG-IP, Zyxel, D-Link devices.


News URL

https://www.bleepingcomputer.com/news/security/dreambus-malware-exploits-rocketmq-flaw-to-infect-servers/