← Back to Feed

Apache ActiveMQ Exploit Leads to LockBit Ransomware

CVE-2023-46604

February 23, 2026 · DFIR Report · Severity: CRITICAL

This intrusion began in mid-February 2024 after a threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server. The actor achieved remote code execution using a Java Spring class, leading to LockBit ransomware deployment.

Key Takeaways

  • Exploit of CVE-2023-46604 on Apache ActiveMQ enables remote code execution.
  • Attack leads to LockBit ransomware deployment on compromised systems.
  • Threat actor used Java Spring class for exploitation and persistence.
☕ Buy a Coffee