Threat reportVulnerabilityTL-2026-0404

Apache ActiveMQ OpenWire Deserialization RCE (CVE-2023-46604) — 6,400 Brokers Actively Exploited by HelloKitty, Kinsing, TellYouThePass and Andariel (Lazarus)

criticalACTIVE

Apache ActiveMQ OpenWire Deserialization RCE (TL-2026-0404), also tracked as Apache ActiveMQ OpenWire Deserialization RCE, is a critical-severity software vulnerability scored CVSS 10, first published 2026-04-21. It is attributed to HelloKitty with high confidence, affects Apache Software Foundation Apache ActiveMQ, references 1 CVE (CVE-2023-46604), maps to 28 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 32 indicators of compromise.

CVSS
10/10Critical
CVEs
1Referenced vulnerabilities
Techniques
28MITRE ATT&CK
Actors
4HelloKitty
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-0404

Threat ID
TL-2026-0404
Also known as
Apache ActiveMQ OpenWire Deserialization RCE, ActiveMQ ClassPathXmlApplicationContext RCE, HelloKitty ActiveMQ Campaign, Andariel ActiveMQ Intrusions
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
HelloKitty, Kinsing, TellYouThePass, Andariel
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
healthcare, manufacturing, financial-services, technology, government, education, energy, telecommunications, retail, transportation, media
Target regions
North America, Europe, Asia-Pacific, South Korea, Japan, Latin America, Middle East
Detection rules
9
Indicators of compromise
32

Malware and tooling in Apache ActiveMQ OpenWire Deserialization RCE

Malware and tooling: HelloKitty / FiveHands, Kinsing, Mauri, Tellyouthepass, Cobalt Strike beacons delivered via CVE-2023-46604 staging, Godzilla Webshell, Metasploit exploit/multi/misc/apache_activemq_rce_cve_2023_46604, NukeSped, SparkRAT

How Apache ActiveMQ OpenWire Deserialization RCE works

CVE-2023-46604 is a CVSS 10.0 unauthenticated remote code execution vulnerability in the OpenWire protocol marshaller of Apache ActiveMQ (and the Legacy OpenWire Module) that lets a network attacker instantiate arbitrary Java classes via a forged ExceptionResponse packet — most commonly Spring's ClassPathXmlApplicationContext — to load a remote XML bean definition that spawns a ProcessBuilder and executes OS commands. As of 2026-04-20 Shadowserver is still tracking ~6,400 internet-facing vulnerable brokers despite patches being available since October 2023, and mass exploitation continues with HelloKitty ransomware, Kinsing cryptominers, TellYouThePass, and the DPRK Andariel/Lazarus subgroup chaining the exploit with Godzilla webshells and ransomware payloads. The bug is trivial to weaponize — a Metasploit module and working GitHub PoCs (X1r0z/ActiveMQ-RCE, sule01u) have existed for over two years — making any exposed broker on TCP/61616 a near-guaranteed initial-access vector for commodity and state-aligned crews alike.

## Overview

CVE-2023-46604 is an insecure-deserialization flaw in Apache ActiveMQ's OpenWire wire protocol, rated CVSS v3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). It was disclosed by Apache on 2023-10-27 and added to the CISA Known Exploited Vulnerabilities catalog on 2023-11-02 with a federal remediation deadline of 2023-11-23. Mass exploitation began the same week as disclosure and has never meaningfully subsided — Shadowserver's 2026-04-20 scan found roughly 6,400 unpatched brokers still reachable on the public internet, a headline statistic that prompted this re-hunt.

## Root Cause

The defect lives in `org.apache.activemq.openwire.v12.BaseDataStreamMarshaller.createThrowable(String className, String message)`. When an OpenWire peer receives an `ExceptionResponse` command (data type 31) the marshaller reads the attacker-controlled `className` and calls `Class.forName(className).getConstructor(String.class).newInstance(message)`. There is no allow-list, no interface check, and no validation that the class actually extends `java.lang.Throwable` — any class with a public single-arg `String` constructor that can be reached on the classpath will be loaded and instantiated.

Because ActiveMQ ships with Spring on the classpath, attackers universally abuse `org.springframework.context.support.ClassPathXmlApplicationContext`. Its `String` constructor treats the argument as a URL to a Spring XML bean definition, fetches it, and instantiates every bean declared inside — typically a `java.lang.ProcessBuilder` bean whose `start()` method is invoked via Spring's `method-invoking-factory-bean` pattern, yielding arbitrary OS command execution as the ActiveMQ service user (often root on Linux, LOCAL SYSTEM or a dedicated service account on Windows).

## Exploitation Chain

1. Attacker stands up an HTTP(S) listener hosting a malicious `poc.xml` Spring bean definition. 2. Attacker opens a raw TCP socket to TCP/61616 (default OpenWire) on the victim broker. 3. Attacker sends a crafted OpenWire frame with command type `0x1F` (ExceptionResponse), setting the exception class name to `org.springframework.context.support.ClassPathXmlApplicationContext` and the message field to the URL of the attacker-hosted XML. 4. Broker unmarshals the frame, calls `Class.forName(...).getConstructor(String.class).newInstance(url)`, fetches the XML, and instantiates the declared `ProcessBuilder` bean. 5. `ProcessBuilder.start()` executes the attacker's command (PowerShell downloader, bash reverse shell, cmd.exe one-liner, etc.). 6. Payload stages the actor's tooling: HelloKitty ransomware binaries (`dllloader`/`M4.dll`), the Godzilla JSP webshell (`/tmp/M2.png` dropped into the admin webapp), Kinsing XMRig miner, or TellYouThePass Go-based encryptor.

The attack is pre-authentication and single-packet; scanning is as simple as a TCP SYN probe to 61616 followed by an OpenWire `WireFormatInfo` handshake, and mass exploitation scripts fire through the chain in under 250ms per host.

## Observed Campaigns

- **2023-10-27 — HelloKitty ransomware**: Rapid7 MDR observed near-zero-day exploitation within 48 hours of disclosure, dropping `M2.png` and `M4.png` (renamed DLLs) and invoking `rundll32.exe` via MSDTC to load the HelloKitty encryptor. Two ransom notes (`!!!READ ME_FOR_DECRYPT!!!.txt`) across encrypted environments. - **2023-11 onward — Kinsing**: cryptominer botnet pivoted within days, using the ActiveMQ RCE as a drop-in replacement for Log4Shell in its exploit rotation; payloads include `kinsing` ELF, `kdevtmpfsi` miner, and the Kinsing rootkit. - **2023-11 — TellYouThePass ransomware**: Go-based cross-platform ransomware delivered via the same ClassPathXmlApplicationContext primitive; Arctic Wolf reported encryption of Linux brokers with `.locked` extension. - **2023-12 — Andariel (Lazarus subgroup, DPRK)**: IBM X-Force attributed long-dwell intrusions at a Korean healthcare and manufacturing target to Andariel, who used CVE-2023-46604 for initial access and then deployed NukeSped, TigerRAT, and a new NetCat-derived reverse shell dubbed 'DTrack-v2'. - **2024 — SparkRAT / Mauri ransomware**: AhnLab ASEC documented Korean-language threat actor deploying SparkRAT and Mauri (custom ransomware) via the same primitive. - **2025–2026 — commodity crypto/crimeware**: Continued 'spray-and-pray' exploitation by cryptomining botnets (Kinsing variants, 8220 Gang) and initial-access brokers selling footholds into financial and manufacturing verticals.

## Why It Persists

ActiveMQ is a long-lived, infrequently-patched infrastructure component — brokers often run for years in message-bus pipelines where downtime requires coordinated change windows. Many deployments are embedded (Alfresco, Red Hat AMQ, Talend, IBM Integration Bus bundles) where operators aren't aware ActiveMQ is underneath. Port 61616 is frequently exposed to the internet by misconfigured cloud load balancers and firewall rules. The result: two-and-a-half years after patching, Shadowserver still finds ~6,400 vulnerable brokers, of which a majority show exploitation telemetry on honeypot sensors within 24 hours of being brought online.

## Fix and Mitigation

Apache released patches in 5.15.16, 5.16.7, 5.17.6, and 5.18.3 on 2023-10-25; the root-cause patch (`BaseDataStreamMarshaller.validateIsThrowable`) now enforces that the unmarshalled class is a subclass of `java.lang.Throwable` before instantiation. Operators who cannot patch immediately must block inbound TCP/61616 from untrusted networks, require TLS+authentication on OpenWire transport connectors (`<transportConnector uri=\"ssl://0.0.0.0:61617?needClientAuth=true\"/>`), and remove Spring from the ActiveMQ classpath if unused. Detection should focus on outbound HTTP fetches from `java` processes to non-corporate hosts, spawning of `ProcessBuilder`-instantiated children under the ActiveMQ service user, and OpenWire frames whose ExceptionResponse class name is not a legitimate JMS exception subclass.

MITRE ATT&CK techniques used in TL-2026-0404

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1218 System Binary Proxy Execution

Exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1496 Resource Hijacking

Persistence

T1505 Server Software Component; T1543 Create or Modify System Process

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

Affected products and versions in Apache ActiveMQ OpenWire Deserialization RCE

  • Apache Software Foundation — Apache ActiveMQ
    Vulnerable versions: 5.18.0 through 5.18.2; 5.17.0 through 5.17.5; 5.16.0 through 5.16.6; 5.15.0 through 5.15.15
    Fixed in: 5.18.3; 5.17.6; 5.16.7; 5.15.16
  • Apache Software Foundation — Apache ActiveMQ Legacy OpenWire Module
    Vulnerable versions: 5.18.0 through 5.18.2; 5.17.0 through 5.17.5; 5.16.0 through 5.16.6; 5.8.0 through 5.15.15
    Fixed in: 5.18.3; 5.17.6; 5.16.7; 5.15.16
  • Red Hat — Red Hat AMQ Broker (embedded ActiveMQ)
    Vulnerable versions: AMQ Broker 7.11.x prior to 7.11.4; AMQ Broker 7.10.x prior to 7.10.5
    Fixed in: AMQ Broker 7.11.4; AMQ Broker 7.10.5
  • Alfresco Software — Alfresco Content Services (embedded ActiveMQ)
    Vulnerable versions: ACS bundles shipping ActiveMQ < 5.17.6
    Fixed in: ACS 23.1 with ActiveMQ 5.17.6+

Remediation for Apache ActiveMQ OpenWire Deserialization RCE

Patches

  • Apache ActiveMQ 5.15.16 (for 5.15.x branch)
  • Apache ActiveMQ 5.16.7 (for 5.16.x branch)
  • Apache ActiveMQ 5.17.6 (for 5.17.x branch)
  • Apache ActiveMQ 5.18.3 (for 5.18.x branch)
  • Apache ActiveMQ Legacy OpenWire Module equivalent releases

Immediate actions

  • Block inbound TCP/61616 (OpenWire) from untrusted networks at perimeter and east-west firewalls; restrict to known JMS client subnets only.
  • Inventory every ActiveMQ broker including embedded instances (Alfresco, Red Hat AMQ, Talend, IBM IB) and map exposure of OpenWire and AMQP ports (61616, 61617, 5672).
  • Hunt for existing compromise: look for child processes of the ActiveMQ JVM (java.exe/java) that are cmd.exe, powershell.exe, bash, sh, curl, wget, or rundll32 — and for outbound HTTP GETs from the JVM to non-Maven hosts.
  • Search for the Godzilla webshell file `/tmp/M2.png` or admin-webapp JSP uploads, and for `M4.dll`, `M4.png` renamed DLLs invoked via rundll32 and MSDTC.

Workarounds

  • If patching is not immediately possible, remove or rename `spring-context-*.jar` from ActiveMQ's `lib/` to break the ClassPathXmlApplicationContext primitive (breaks Spring-based camel routes).
  • Restrict OpenWire transport to loopback or a management VLAN and proxy client traffic through an authenticated gateway (e.g., HAProxy with mTLS).
  • Deploy a WAF/L7 proxy in front of 61616 that rejects OpenWire ExceptionResponse frames whose class name is not on an allow-list of known JMSException subclasses.

Longer-term hardening

  • Patch to Apache ActiveMQ 5.15.16 / 5.16.7 / 5.17.6 / 5.18.3 or later — the Legacy OpenWire Module fixes are rolled into these releases.
  • Enable TLS + mutual authentication on OpenWire transport connectors and disable anonymous access in activemq.xml (`<authorizationPlugin>` + `<simpleAuthenticationPlugin>` at minimum, preferably JAAS).
  • Remove Spring from the ActiveMQ classpath if not used by any deployed plugins; this neutralises the most common ClassPathXmlApplicationContext primitive.
  • Deploy EDR with Java process-lineage rules and Suricata/Snort signatures for OpenWire ExceptionResponse class-name anomalies.
  • Subscribe brokers to Apache ActiveMQ security advisories and track the Legacy OpenWire Module CVE stream (CVE-2023-46604, CVE-2024-32114, CVE-2025-27533).

CVEs associated with Apache ActiveMQ OpenWire Deserialization RCE

CVE-2023-46604

Weaknesses (CWE) in Apache ActiveMQ OpenWire Deserialization RCE

CWE-502, CWE-20, CWE-913, CWE-470

Timeline of Apache ActiveMQ OpenWire Deserialization RCE

  • Apache commits validateIsThrowable fix to activemq repo (commit 40689541); 5.15.16 / 5.16.7 / 5.17.6 / 5.18.3 release artifacts produced.
  • X1r0z publishes working ActiveMQ-RCE PoC on GitHub, enabling trivial mass exploitation.
  • Rapid7 MDR detects first in-the-wild exploitation dropping HelloKitty ransomware via rundll32+MSDTC chain, within hours of disclosure.
  • Apache Software Foundation publishes CVE-2023-46604 advisory on activemq.apache.org/security-advisories; CVSS 10.0 assigned.
  • sule01u and multiple other researchers release Python/Go variants of the exploit; Nuclei template published.
  • Rapid7 publishes detailed exploitation analysis and technical deep-dive on Emergent Threat Response blog.
  • Rapid7 merges activemq_openwire_deserialization Metasploit module (PR #18456) to master branch.
  • CISA adds CVE-2023-46604 to Known Exploited Vulnerabilities Catalog with federal remediation deadline 2023-11-23.
  • Arctic Wolf confirms TellYouThePass ransomware deploying via CVE-2023-46604 against Linux-hosted brokers.
  • Trend Micro reports Kinsing cryptomining botnet integrates the exploit into its automated infection chain.
  • IBM X-Force attributes long-dwell intrusions at Korean targets to Andariel (Lazarus subgroup) using CVE-2023-46604 for initial access and deploying NukeSped/TigerRAT.
  • AhnLab ASEC documents Mauri ransomware campaigns using the same primitive with SparkRAT as staging tool.
  • Shadowserver quarterly scans continue to find 7,000+ vulnerable brokers two years post-patch.
  • Shadowserver publishes 2026-04-20 dashboard: ~6,400 internet-facing vulnerable ActiveMQ brokers still detected; BleepingComputer amplifies the finding.
  • Threadlinqs Intelligence opens TL-2026-0404 to re-track campaign, refresh IOCs, and publish updated detections.
  • As of 2026-05-29, CVE-2023-46604 (Apache ActiveMQ OpenWire RCE) remains actively exploited despite patches: a Feb-2026 DFIR Report tied it to LockBit ransomware and Kinsing's Sharpire backdoor campaign ran into March 2026. Shadowserver still tracks thousands of exposed brokers, keeping any unpatched TCP/61616 broker a live initial-access vector.

Sources cited for Apache ActiveMQ OpenWire Deserialization RCE

Detection coverage for TL-2026-0404

As of 2026-04-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0404 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats