VORANT. Threat Intelligence Sign in Get the full feed

LockBit builder abused via ActiveMQ flaw

high threat

An unpatched Apache ActiveMQ server exploited via CVE-2023-46604 led to Metasploit-based intrusion and deployment of LockBit ransomware built from the leaked builder.

The DFIR Report details an intrusion beginning in mid-February 2024 when a threat actor exploited CVE-2023-46604, a remote code execution vulnerability in Apache ActiveMQ, on an internet-facing server. Using a malicious Java Spring bean configuration XML delivered via OpenWire, the actor executed commands via CertUtil to download a Metasploit stager. Post-exploitation activity included privilege escalation via Meterpreter's getsystem, LSASS credential dumping, SMB-based network scanning, and lateral movement using a compromised domain administrator account. The actor was evicted after roughly a day but returned 18 days later through the same unpatched vulnerability, reusing the same C2 infrastructure (166.62.100.52) and previously harvested credentials.

On regaining access, the actor moved quickly to ransomware deployment: installing AnyDesk for persistence, running Advanced IP Scanner disguised as SoftPerfect, and using RDP with a privileged service account to reach backup, file, and domain controller servers. Ransomware binaries (LB3.exe and LB3_pass.exe) were manually copied and executed across multiple hosts over roughly four hours. Analysis of the ransom note — which directed victims to the Session messaging app instead of standard LockBit Tor/TOX infrastructure — indicates the binaries were built using the leaked LockBit Black builder, suggesting an independent actor operating under the LockBit brand rather than official LockBit affiliate infrastructure.

The case highlights the risk of delayed patching: the initial compromise went undetected for weeks, and had the second intrusion not reused known infrastructure and TTPs, the organization would have had less than 90 minutes between re-engagement and full ransomware execution. Total time-to-ransomware was approximately 419 hours (19 days), reinforcing the value of early detection during the reconnaissance and lateral movement phases.

Mentioned in this report

Vulnerabilities CVE-2023-46604KEV
Threat actors LockBit
Malware Advanced IP ScannerAnyDeskLockBit BlackMetasploit stagerMeterpreter

Source reporting: https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free