# Apache ActiveMQ OpenWire Deserialization RCE (CVE-2023-46604) — 6,400 Brokers Actively Exploited by HelloKitty, Kinsing, TellYouThePass and Andariel (Lazarus)

> CVE-2023-46604 is a CVSS 10.0 unauthenticated remote code execution vulnerability in the OpenWire protocol marshaller of Apache ActiveMQ (and the Legacy OpenWire Module) that lets a network attacker instantiate arbitrary Java classes via a forged ExceptionResponse packet — most commonly Spring's ClassPathXmlApplicationContext — to load a remote XML bean definition that spawns a ProcessBuilder and executes OS commands. As of 2026-04-20 Shadowserver is still tracking ~6,400 internet-facing vulnerable brokers despite patches being available since October 2023, and mass exploitation continues with HelloKitty ransomware, Kinsing cryptominers, TellYouThePass, and the DPRK Andariel/Lazarus subgroup chaining the exploit with Godzilla webshells and ransomware payloads. The bug is trivial to weaponize — a Metasploit module and working GitHub PoCs (X1r0z/ActiveMQ-RCE, sule01u) have existed for over two years — making any exposed broker on TCP/61616 a near-guaranteed initial-access vector for commodity and state-aligned crews alike.

- **Published:** 2026-04-21T12:00:00Z
- **Last reviewed:** 2026-04-21T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0404
- **ID:** TL-2026-0404
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** HelloKitty
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2023-46604

## Description

## Overview

CVE-2023-46604 is an insecure-deserialization flaw in Apache ActiveMQ's OpenWire wire protocol, rated CVSS v3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). It was disclosed by Apache on 2023-10-27 and added to the CISA Known Exploited Vulnerabilities catalog on 2023-11-02 with a federal remediation deadline of 2023-11-23. Mass exploitation began the same week as disclosure and has never meaningfully subsided — Shadowserver's 2026-04-20 scan found roughly 6,400 unpatched brokers still reachable on the public internet, a headline statistic that prompted this re-hunt.

## Root Cause

The defect lives in `org.apache.activemq.openwire.v12.BaseDataStreamMarshaller.createThrowable(String className, String message)`. When an OpenWire peer receives an `ExceptionResponse` command (data type 31) the marshaller reads the attacker-controlled `className` and calls `Class.forName(className).getConstructor(String.class).newInstance(message)`. There is no allow-list, no interface check, and no validation that the class actually extends `java.lang.Throwable` — any class with a public single-arg `String` constructor that can be reached on the classpath will be loaded and instantiated.

Because ActiveMQ ships with Spring on the classpath, attackers universally abuse `org.springframework.context.support.ClassPathXmlApplicationContext`. Its `String` constructor treats the argument as a URL to a Spring XML bean definition, fetches it, and instantiates every bean declared inside — typically a `java.lang.ProcessBuilder` bean whose `start()` method is invoked via Spring's `method-invoking-factory-bean` pattern, yielding arbitrary OS command execution as the ActiveMQ service user (often root on Linux, LOCAL SYSTEM or a dedicated service account on Windows).

## Exploitation Chain

1. Attacker stands up an HTTP(S) listener hosting a malicious `poc.xml` Spring bean definition.
2. Attacker opens a raw TCP socket to TCP/61616 (default OpenWire) on the victim broker.
3. Attacker sends a crafted OpenWire frame with command type `0x1F` (ExceptionResponse), setting the exception class name to `org.springframework.context.support.ClassPathXmlApplicationContext` and the message field to the URL of the attacker-hosted XML.
4. Broker unmarshals the frame, calls `Class.forName(...).getConstructor(String.class).newInstance(url)`, fetches the XML, and instantiates the declared `ProcessBuilder` bean.
5. `ProcessBuilder.start()` executes the attacker's command (PowerShell downloader, bash reverse shell, cmd.exe one-liner, etc.).
6. Payload stages the actor's tooling: HelloKitty ransomware binaries (`dllloader`/`M4.dll`), the Godzilla JSP webshell (`/tmp/M2.png` dropped into the admin webapp), Kinsing XMRig miner, or TellYouThePass Go-based encryptor.

The attack is pre-authentication and single-packet; scanning is as simple as a TCP SYN probe to 61616 followed by an OpenWire `WireFormatInfo` handshake, and mass exploitation scripts fire through the chain in under 250ms per host.

## Observed Campaigns

- **2023-10-27 — HelloKitty ransomware**: Rapid7 MDR observed near-zero-day exploitation within 48 hours of disclosure, dropping `M2.png` and `M4.png` (renamed DLLs) and invoking `rundll32.exe` via MSDTC to load the HelloKitty encryptor. Two ransom notes (`!!!READ ME_FOR_DECRYPT!!!.txt`) across encrypted environments.
- **2023-11 onward — Kinsing**: cryptominer botnet pivoted within days, using the ActiveMQ RCE as a drop-in replacement for Log4Shell in its exploit rotation; payloads include `kinsing` ELF, `kdevtmpfsi` miner, and the Kinsing rootkit.
- **2023-11 — TellYouThePass ransomware**: Go-based cross-platform ransomware delivered via the same ClassPathXmlApplicationContext primitive; Arctic Wolf reported encryption of Linux brokers with `.locked` extension.
- **2023-12 — Andariel (Lazarus subgroup, DPRK)**: IBM X-Force attributed long-dwell intrusions at a Korean healthcare and manufacturing target to Andariel, who used CVE-2023-46604 for initial access and then deployed NukeSped, TigerRAT, and a new NetCat-derived reverse shell dubbed 'DTrack-v2'.
- **2024 — SparkRAT / Mauri ransomware**: AhnLab ASEC documented Korean-language threat actor deploying SparkRAT and Mauri (custom ransomware) via the same primitive.
- **2025–2026 — commodity crypto/crimeware**: Continued 'spray-and-pray' exploitation by cryptomining botnets (Kinsing variants, 8220 Gang) and initial-access brokers selling footholds into financial and manufacturing verticals.

## Why It Persists

ActiveMQ is a long-lived, infrequently-patched infrastructure component — brokers often run for years in message-bus pipelines where downtime requires coordinated change windows. Many deployments are embedded (Alfresco, Red Hat AMQ, Talend, IBM Integration Bus bundles) where operators aren't aware ActiveMQ is underneath. Port 61616 is frequently exposed to the internet by misconfigured cloud load balancers and firewall rules. The result: two-and-a-half years after patching, Shadowserver still finds ~6,400 vulnerable brokers, of which a majority show exploitation telemetry on honeypot sensors within 24 hours of being brought online.

## Fix and Mitigation

Apache released patches in 5.15.16, 5.16.7, 5.17.6, and 5.18.3 on 2023-10-25; the root-cause patch (`BaseDataStreamMarshaller.validateIsThrowable`) now enforces that the unmarshalled class is a subclass of `java.lang.Throwable` before instantiation. Operators who cannot patch immediately must block inbound TCP/61616 from untrusted networks, require TLS+authentication on OpenWire transport connectors (`<transportConnector uri=\"ssl://0.0.0.0:61617?needClientAuth=true\"/>`), and remove Spring from the ActiveMQ classpath if unused. Detection should focus on outbound HTTP fetches from `java` processes to non-corporate hosts, spawning of `ProcessBuilder`-instantiated children under the ActiveMQ service user, and OpenWire frames whose ExceptionResponse class name is not a legitimate JMS exception subclass.

## MITRE ATT&CK

- T1595 Active Scanning
- T1590 Gather Victim Network Information
- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1587 Develop Capabilities
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1203 Exploitation for Client Execution
- T1505 Server Software Component
- T1543 Create or Modify System Process
- T1068 Exploitation for Privilege Escalation
- T1218 System Binary Proxy Execution
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1070 Indicator Removal
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1046 Network Service Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1571 Non-Standard Port
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1496 Resource Hijacking
- T1489 Service Stop

## Sources

- [Apache ActiveMQ Security Advisory CVE-2023-46604 — Announcement](https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt)
- [CISA KEV Catalog — CVE-2023-46604 Apache ActiveMQ Deserialization](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [NVD — CVE-2023-46604](https://nvd.nist.gov/vuln/detail/CVE-2023-46604)
- [Rapid7 — Suspected Exploitation of Apache ActiveMQ CVE-2023-46604](https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/)
- [Shadowserver — Apache ActiveMQ CVE-2023-46604 Exploitation Trends](https://www.shadowserver.org/news/apache-activemq-cve-2023-46604-exploitation-trends/)
- [BleepingComputer — 6,400 Apache ActiveMQ Servers Exposed to Actively Exploited Flaw](https://www.bleepingcomputer.com/news/security/6400-apache-activemq-servers-exposed-to-actively-exploited-flaw/)
- [IBM X-Force — Andariel (Lazarus) Exploits Apache ActiveMQ](https://securityintelligence.com/x-force/andariel-exploits-apache-activemq/)
- [Arctic Wolf — TellYouThePass Ransomware Exploits CVE-2023-46604](https://arcticwolf.com/resources/blog/tellyouthepass-ransomware-cve-2023-46604/)
- [Trend Micro — Kinsing Exploits CVE-2023-46604 to Deploy Cryptomining Malware](https://www.trendmicro.com/en_us/research/23/k/kinsing-exploit-activemq.html)
- [AhnLab ASEC — Mauri Ransomware Distributed via ActiveMQ Vulnerability](https://asec.ahnlab.com/en/61230/)
- [X1r0z — ActiveMQ-RCE Public Proof-of-Concept](https://github.com/X1r0z/ActiveMQ-RCE)
- [sule01u — CVE-2023-46604 Exploit Script](https://github.com/sule01u/CVE-2023-46604)
- [Rapid7 Metasploit Module — activemq_openwire_deserialization](https://github.com/rapid7/metasploit-framework/pull/18456)
- [Apache ActiveMQ Source Fix Commit (5.18.3)](https://github.com/apache/activemq/commit/40689541f1b29d40302e5fa09e7fa9f7a7a19b8d)
- [Fortiguard — Threat Signal Apache ActiveMQ RCE](https://fortiguard.fortinet.com/threat-signal-report/5299)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0404
