Debt Financing Nexus
No Result
View All Result
  • Login
  • Home
  • Business
  • Finance
  • Mortgage
  • Banking
  • Credit Cards
  • Investing
  • Loans
  • Saving
  • Taxes
  • More
    • Markets
    • Economy
    • Real Estate
    • Crypto
Subscribe For Alerts
  • Home
  • Business
  • Finance
  • Mortgage
  • Banking
  • Credit Cards
  • Investing
  • Loans
  • Saving
  • Taxes
  • More
    • Markets
    • Economy
    • Real Estate
    • Crypto
No Result
View All Result
Debt Financing Nexus
No Result
View All Result
Home Crypto

Hackers Exploit Apache ActiveMQ Flaw To Mine Crypto

News Room by News Room
November 22, 2023
Reading Time: 2 mins read
0
Hackers Exploit Apache ActiveMQ Flaw To Mine Crypto
Source: Pixabay

Hackers are currently targeting a critical Apache ActiveMQ vulnerability to download and infect Linux machines with the Kinsing malware and crypto miner.

In a blog post published on November 20, Trend Micro researchers reported that the exploitation of the CVE-2023-46604 vulnerability in the open-source ActiveMQ protocol results in remote code execution (RCE), which allows Kinsing to carry out the download and installation of malware.

Following a system infection, Kinsing deploys a cryptocurrency-mining script that exploits the host’s resources to mine cryptocurrencies such as Bitcoin. This not only leads to substantial damage to infrastructure but also adversely affects system performance.

The Kinsing malware poses a significant threat, focusing primarily on Linux-based systems, the researchers added. This malicious software has the capability to infiltrate servers and spread rapidly throughout a network. Its mode of entry involves exploiting vulnerabilities present in web applications or misconfigured container environments.

“Organizations that use Apache ActiveMQ must take immediate action to patch CVE-2023-46604 as soon as possible and mitigate the risks associated with Kinsing,” the researchers said in the post. “Given the malware’s ability to spread across networks and exploit multiple vulnerabilities, it is important to maintain up-to-date security patches, regularly audit configurations, and monitor network traffic for unusual activity, all of which are critical components of a comprehensive cybersecurity strategy.”

The vulnerability’s root cause lies in a problem related to the validation of throwable class types during the unmarshalling of OpenWire commands, the researchers noted.

Reports emerged earlier this month regarding the active exploitation of CVE-2023-46604, with hackers utilizing exploits like Metasploit and Nuclei. Despite the high severity of the vulnerability, rated at CVSS 9.8, the level of detection remains comparatively low.

John Gallagher, vice president of Viakoo Labs, highlighted the significance of the CVE, emphasizing the widespread use of Apache ActiveMQ and its ability to communicate across multiple protocols. Additionally, he pointed out its extensive utilization in non-IT environments for interfacing with IoT/OT/ICS devices.

Gallagher further noted that many organizations face challenges in maintaining the patching of IoT devices. Given this scenario, Kinsing’s strategic choice to exploit this vulnerability aligns well with their objective of sustained processing, particularly for activities such as cryptomining.

“Many IoT devices have powerful processing capabilities and lack patching policies, making mining an ideal activity for them,” said Gallagher. “To put it another way, Kinsing likely chose to use this CVE for crypto mining because they expect it to be a long-lived vulnerability; it wouldn’t make any sense if it was a vulnerability Kinsing was expecting to get patched quickly.”


Enter your email for our Free Daily Newsletter

A quick 3min read about today’s crypto news!

Read the full article here

ShareTweetSendSend

Related Posts

Crypto Analysts Say TG.Casino ($TGC) GameFi Coin Can Explode Like Rollbit After it Raises $3m, Just $2m Left
Crypto

Crypto Analysts Say TG.Casino ($TGC) GameFi Coin Can Explode Like Rollbit After it Raises $3m, Just $2m Left

November 28, 2023
As PEPE100 Leaps 50x Overnight, This Hidden Crypto Just Surpassed $1.8 Million in Funding – 100x Possible?
Crypto

As PEPE100 Leaps 50x Overnight, This Hidden Crypto Just Surpassed $1.8 Million in Funding – 100x Possible?

November 27, 2023
Square Enix’s NFT Game Symbiogenesis Sets Auction Dates, Launches December 21 – Here’s What You Need to Know
Crypto

Square Enix’s NFT Game Symbiogenesis Sets Auction Dates, Launches December 21 – Here’s What You Need to Know

November 27, 2023
Terra Luna Classic Price Prediction as LUNC Rockets Up 50% in 24 Hours – Can LUNC Reach $1 Soon?
Crypto

Terra Luna Classic Price Prediction as LUNC Rockets Up 50% in 24 Hours – Can LUNC Reach $1 Soon?

November 27, 2023
HTX Resumes Bitcoin and Ether Services After $30 Million Hack
Crypto

HTX Resumes Bitcoin and Ether Services After $30 Million Hack

November 27, 2023
Zipmex Thailand Suspends Crypto Trading Citing Compliance With the Country’s SEC Rules
Crypto

Zipmex Thailand Suspends Crypto Trading Citing Compliance With the Country’s SEC Rules

November 27, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Debt Financing Nexus

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • Trump calls for 1-year 10% cap on credit card interest rates
  • 45 sickened with salmonella in connection with recall of Super Greens diet supplement powder
  • Americans flee mortgage market despite lower rates as lenders tighten grip on credit nationwide

Categories

  • Banking
  • Business
  • Credit Cards
  • Crypto
  • Economy
  • Finance
  • Investing
  • Loans
  • Markets
  • Mortgage
  • Real Estate
  • Saving
  • Taxes
  • Uncategorized
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

© 2025 Debt Financing Nexus. All Rights Reserved.

No Result
View All Result
  • Home
  • Business
  • Finance
  • Mortgage
  • Banking
  • Credit Cards
  • Investing
  • Loans
  • Saving
  • Taxes
  • More
    • Markets
    • Economy
    • Real Estate
    • Crypto

© 2025 Debt Financing Nexus. All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.