• News/
  • https://www.zdnet.com/article/dripdropper-linux-malware-cleans-up-after-itself/

DripDropper Linux malware cleans up after itself - how it works

ZDNet
·
Steven Vaughan-Nichols
·
Published Aug 19, 2025
·
Updated

Get more in-depth ZDNET tech coverage: Add us as a preferred Google source on Chrome and Chromium browsers. The security company Red Canary has detected an attacker exploiting Apache ActiveMQ, a popular open-source message broker, security hole CVE-2023-46604, to gain persistent access on cloud Linux systems. So far, so much villainy as usual. Where DripDropper changes the game is that, once it's in, it patches the security hole behind it. Also: The best VPN services (and how to choose the right one for you) This unusual, but not unheard of tactic, has two purposes. The first is to lock out other malware programs. The other is to mask its presence so you miss spotting its mischief. "It's unusual to see adversaries 'fix' the very systems they've compromised, but this strategy ensures their access stays exclusive and makes initial exploitation harder to trace," said the Red Canary team. According to Red Canary, DripDropper has been working for a while. What's especially annoying about this situation is that the security hole in the Java OpenWire protocol has been patched for almost two years. Why anyone would be running an ActiveMQ instance that has such a serious bug -- the Apache Software Foundation gave it a maximum danger rating of 10 on the Common Vulnerability Scoring System (CVSS) scale -- is beyond me. Also: Cisco patches critical security hole in Firewall Management Center - act now Needless to say, once in, DripDropper deploys Command and Control (C2) frameworks such ...

Read full article

Affected Software

1 affected component
Apache ActiveMQ
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the DripDropper Linux malware that cleans up after itself and its method of operation.

2

What security implications are discussed in the article?

The article highlights the exploitation of vulnerabilities in Apache ActiveMQ and its consequences for system security.

3

What products or software are affected by DripDropper malware?

The DripDropper malware specifically affects Apache ActiveMQ, a widely used open-source message broker.

4

Who detected the DripDropper Linux malware and its exploitation method?

The security firm Red Canary detected the DripDropper Linux malware and provided insights into how attackers exploit it.

5

How does DripDropper malware manage its footprint on infected systems?

DripDropper malware is designed to clean up after itself, minimizing traces of its presence on compromised systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203