Apache ActiveMQ Exploit Leads to LockBit Ransomware

2026-03-04T22:42:52Z4ff458b4685952c2fe461e309921388933b38ffd53a73b76b4f3e9b104334112
CVE-2023-22527CVE-2023-46604AkiraApache ActiveMQBumblebeeConfluenceInterlock RATJava SpringLockBitLynxRDPRansomHubSEO poisoningexposed servicesinitial accesspassword sprayransomwareremote code execution

What happened

Collection of DFIR Report incident write-ups describing multiple ransomware intrusions and malware campaigns driven by exploitation of internet-exposed services and weak remote access. Notable incidents include an Apache ActiveMQ RCE exploit (CVE-2023-46604) leading to LockBit deployment via a Java Spring gadget, Confluence template-injection exploitation (CVE-2023-22527) leading to ransomware, RDP-based access (including password-spray/single successful logon) leading to RansomHub and Lynx deployments, SEO-poisoning and Bumblebee leading to Akira, a new PHP-based Interlock RAT variant, and 's

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
thedfirreport
Record identifier
4ff458b4685952c2fe461e309921388933b38ffd53a73b76b4f3e9b104334112
Enrichment time
2026-03-04T22:42:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.