← Back to Feed
Apache ActiveMQ Exploit Leads to LockBit Ransomware
CVE-2023-46604
February 23, 2026 · DFIR Report · Severity: CRITICAL
This intrusion began in mid-February 2024 after a threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server. The actor achieved remote code execution using a Java Spring class, leading to LockBit ransomware deployment.
Key Takeaways
- Exploit of CVE-2023-46604 on Apache ActiveMQ enables remote code execution.
- Attack leads to LockBit ransomware deployment on compromised systems.
- Threat actor used Java Spring class for exploitation and persistence.