Security News > 2023 > November > HelloKitty ransomware now exploiting Apache ActiveMQ flaw in attacks
![HelloKitty ransomware now exploiting Apache ActiveMQ flaw in attacks](/static/build/img/news/hellokitty-ransomware-now-exploiting-apache-activemq-flaw-in-attacks-medium.jpg)
The HelloKitty ransomware operation is exploiting a recently disclosed Apache ActiveMQ remote code execution flaw to breach networks and encrypt devices.
Yesterday, Rapid7 reported that they had seen at least two distinct cases of threat actors exploiting CVE-2023-46604 in customer environments to deploy HelloKitty ransomware binaries and extort the targeted organizations.
HelloKitty is a ransomware operation that launched in November 2020 and recently had its source code leaked on a Russian-speaking cybercrime forums making it available to anyone.
The Rapid7 report contains information about the latest HelloKitty indicators of compromise, but more comprehensive data on that front can be found in this FBI report focused on the ransomware family.
3,000 Apache ActiveMQ servers vulnerable to RCE attacks exposed online.
Ransomware gangs now exploiting critical TeamCity RCE flaw.
News URL
Related news
- London hospitals left in critical condition after ransomware attack (source)
- Major London hospitals disrupted by Synnovis ransomware attack (source)
- Qilin ransomware gang linked to attack on London hospitals (source)
- Muhstik Botnet Exploiting Apache RocketMQ Flaw to Expand DDoS Attacks (source)
- London hospitals face blood shortage after Synnovis ransomware attack (source)
- Black Basta ransomware gang linked to Windows zero-day attacks (source)
- Panera warns of employee data breach after March ransomware attack (source)
- Toronto District School Board hit by a ransomware attack (source)
- CISA warns of Windows bug exploited in ransomware attacks (source)
- London hospitals cancel over 800 operations after ransomware attack (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-27 | CVE-2023-46604 | Deserialization of Untrusted Data vulnerability in multiple products The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. | 9.8 |