Circumstances of the Andariel Group Exploiting an Apache ActiveMQ Vulnerability (CVE-2023-46604)

2023-11-27 • Ahnlab •

https://asec.ahnlab.com/en/59318/

Thumbnail for Circumstances of the Andariel Group Exploiting an Apache ActiveMQ Vulnerability (CVE-2023-46604)

ASEC reports that Andariel is suspected of exploiting Apache ActiveMQ CVE-2023-46604 to install malware on targeted systems. The activity delivered NukeSped and TigerRat backdoors, with follow-on commands observed for downloading additional payloads and executing malicious scripts. The report places the activity in Andariel's broader targeting of South Korean organizations and its history of using vulnerability exploitation alongside spear phishing, watering-hole, supply-chain, Log4Shell, TeamCity, and MS-SQL server attacks.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9f90670d2197496f7d9d20152fe8222… 2023-11-10 2024-07-25
HASH 383a1f80a99089e4716ed1ad308f66e… 2023-11-17 2023-11-27
HASH 0112b5d175f5b5905a744c69bf263e7… 2023-11-17 2023-11-27
HASH 25a3b5e8f07befa6809d000cf0e4192… 2023-11-17 2023-11-27
HASH 58cbe4315620fa8c46317d57e20aa56… 2023-11-17 2023-11-27
HASH 8177455ab89cc96f0c26bc42907da1a… 2023-11-17 2023-11-27
HASH dd13cf13c1fbdc76da63e76adcf3672… 2023-11-17 2023-11-27
HASH bc024b4bca0d444ca12e42e1a692154… 2023-11-17 2023-11-27
HASH c3c0cf25d682e981c7ce1cc0a00fa2b… 2023-11-17 2023-11-27
HASH 4eead95202e6a0e4936f681fd5579582 2023-11-17 2023-11-27
HASH 160f7d2307bbc0e8a1b6ac03b8715e4f 2023-11-17 2023-11-27
IPv4 206.166.251.186 2023-11-17 2023-11-27
IPv4 137.175.17.172 2023-11-17 2023-11-27
IPv4 27.102.114.215 2023-11-17 2023-11-27
IPv4 137.175.17.221 2023-11-17 2023-11-27
IPv4 168.100.9.154 2023-11-17 2023-11-27
IPv4 176.105.255.60 2023-11-17 2023-11-27
IPv4 27.102.128.152 2023-11-10 2023-11-27

Related Actors

First seen: Jul 2017
Last seen: Sep 2026

Related Reports

« Back