Case of ActiveMQ Vulnerability Exploitation to Install Sharpire (Kinsing)

Case of ActiveMQ Vulnerability Exploitation to Install Sharpire (Kinsing)

AhnLab SEcurity intelligence Center (ASEC) has confirmed that the Kinsing threat actor is still distributing malware by exploiting known vulnerabilities. Since the disclosure of the CVE-2023-46604 vulnerability in ActiveMQ, the threat actor has been exploiting it to install malware on both Linux and Windows systems. [1] Aside from the well-known XMRig

Linux Persistence Techniques Detected by AhnLab EDR (1)

Linux Persistence Techniques Detected by AhnLab EDR (1)

Persistence techniques refer to methods employed by threat actors to maintain a connection to the target system after infiltration. As a single breach may not be enough to achieve all their goals, threat actors look for ways to re-access the system. Persistence can be maintained by configuring the malware to