• News/
  • https://www.theregister.com/2025/08/19/apache_activemq_patch_malware/

Like burglars closing a door, Apache ActiveMQ attackers patch critical vuln after breaking in

The Register
·
Iain Thomson
·
Published Aug 19, 2025
·
Updated

Criminals exploiting a critical vulnerability in open source Apache ActiveMQ middleware are fixing the flaw that allowed them access, after establishing persistence on Linux servers. Researchers at security house Red Canary observed attackers using a new form of Linux malware, dubbed DripDropper, against dozens of systems running Apache's Java-based message broker. The miscreants got in using CVE-2023-46604, a CVSS 9.8 critical flaw that Apache itself rates as a perfect 10. After installing a backdoor to the infected systems, they then downloaded two Java Archive (JAR) files that effectively patched the original vuln. "This kind of behavior is very uncommon, we see it very rarely," Brian Donohue, principal researcher at Red Canary, told The Register. "I think we've only seen it once before and it's not something that happens very often. Most threats are pretty much point and play and don't often include this sort of really customized trick." The criminals gained access using a Sliver implant - a legitimate tool for pentesters but one which is also much abused by black hats - to modify the sshd configuration file of the target machine to allow root access. They then downloaded DripDropper, an encrypted PyInstaller-built ELF that communicates with an attacker-controlled Dropbox account, to maintain control over compromised Linux servers. While patching the systems after infection will help conceal the intrusion from vulnerability scanners, there is a second line of defense agai...

Read full article

Affected Software

1 affected component
Apache ActiveMQ
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Apache ActiveMQ that has been exploited by attackers who are also fixing the flaw post-exploitation.

2

What security implications are discussed?

The article highlights the risks associated with attackers gaining access to systems through a vulnerability and then establishing persistence.

3

What products or software are affected?

The software affected by the vulnerability is Apache ActiveMQ.

4

Who are the attackers mentioned in the article?

The attackers are criminals exploiting the vulnerability in Apache ActiveMQ middleware.

5

What action are the attackers taking regarding the vulnerability?

The attackers are patching the critical vulnerability they exploited after gaining access to the servers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203