Apache ActiveMQ Exploit Leads to LockBit Ransomware
2026-03-04T22:42:52Z•4ff458b4685952c2fe461e309921388933b38ffd53a73b76b4f3e9b104334112
CVE-2023-22527CVE-2023-46604AkiraApache ActiveMQBumblebeeConfluenceInterlock RATJava SpringLockBitLynxRDPRansomHubSEO poisoningexposed servicesinitial accesspassword sprayransomwareremote code execution
What happened
Collection of DFIR Report incident write-ups describing multiple ransomware intrusions and malware campaigns driven by exploitation of internet-exposed services and weak remote access. Notable incidents include an Apache ActiveMQ RCE exploit (CVE-2023-46604) leading to LockBit deployment via a Java Spring gadget, Confluence template-injection exploitation (CVE-2023-22527) leading to ransomware, RDP-based access (including password-spray/single successful logon) leading to RansomHub and Lynx deployments, SEO-poisoning and Bumblebee leading to Akira, a new PHP-based Interlock RAT variant, and 's
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- thedfirreport
- Record identifier
- 4ff458b4685952c2fe461e309921388933b38ffd53a73b76b4f3e9b104334112
- Enrichment time
- 2026-03-04T22:42:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.