ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

GoTitan Botnet and PrCtrl RAT Exploit Apache Vulnerability

criticalVulnerabilityimportance 60CVE-2023-46604

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-46604
Unauthenticated RCE in Apache ActiveMQ via OpenWire Deserialization

CVE-2023-46604 is a critical deserialization flaw (CWE-502) in the Java OpenWire protocol marshaller of Apache ActiveMQ that permits unauthenticated remote code execution (CVSS 9.8). An attacker with network access to either a Java-based OpenWire broker or client can manipulate serialized class types in the OpenWire protocol, causing the peer to instantiate arbitrary classes on the classpath and execute arbitrary shell commands. Successful exploitation yields full command execution on the target broker or client, with no authentication or user interaction required. Affected parties include anyone running ActiveMQ broker or Java client versions prior to 5.15.16, 5.16.7, 5.17.6, or 5.18.3, as well as NetApp E-Series products and Debian packages that ship affected ActiveMQ/OpenWire components. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-11-02 with known ransomware use (RansomHub), and has been used to drop Kinsing malware, Godzilla web shells, and the DripDropper implant, in some cases with attackers patching the flaw post-exploitation to lock out competing intruders.

Do: Upgrade all ActiveMQ brokers and Java OpenWire clients to 5.15.16, 5.16.7, 5.17.6, or 5.18.3 (or later), and apply the relevant NetApp E-Series and Debian updates for bundled components; restrict the OpenWire port (default TCP 61616) from untrusted networks. Hunt for indicators of the documented campaigns (Godzilla web shells, Kinsing malware, DripDropper, RansomHub) and verify the broker's current version, since attackers have been observed patching the flaw post-exploitation to hide from defenders. The CISA KEV listing means federal agencies must apply vendor mitigations or discontinue use of the product.

9.8100% KEV ransomware PoC
  • apache activemq Java-based OpenWire brokers and clients prior to 5.15.16, 5.16.7, 5.17.6, and 5.18.3
  • apache activemq legacy openwire module OpenWire marshaller as shipped in releases prior to the fixed versions 5.15.16 / 5.16.7 / 5.17.6 / 5.18.3
  • debian linux
  • +3 more
largetens of thousands of internet-exposed OpenWire brokers (order of 10,000–100,000 by public scans), plus uncounted internal deployments and bundled NetApp/Debian…
Full article351 words · extracted from infosecurity-magazine.com · click to collapse

Threat actors have been observed exploiting a critical vulnerability, CVE-2023-46604, in Apache systems. 

Over the past few weeks, Fortiguard Labs identified multiple threat actors leveraging this vulnerability to unleash several malware strains.

Among the discoveries is the emergence of a newly discovered Golang-based botnet named GoTitan. This sophisticated botnet has raised concerns due to its ability to disseminate diverse malware strains. 

GoTitan has been observed downloading from a malicious URL and exhibits a specific focus on x64 architectures. Furthermore, the malware, while still in an early stage of development, replicates itself within systems, establishes recurring execution through cron registration and collects essential information about compromised endpoints.

A .NET program called PrCtrl Rat has also surfaced as a cyber-threat targeting the Apache flaw. The malicious software, equipped with remote control capabilities, uses a .NET framework, allowing it to execute commands and potentially establish a persistent presence on compromised systems.

Furthermore, the researchers have pinpointed the presence of other familiar malware and tools in the ongoing exploits. Sliver, created as an advanced penetration testing tool and red teaming framework, has been used maliciously by threat actors. It supports diverse callback protocols such as DNS, TCP and HTTP(S), simplifying exit processes. 

Fortiguard added that Kinsing has also established itself as a force in cryptojacking operations, demonstrating a swift ability to exploit newly uncovered vulnerabilities. 

Read more on these attacks: Flaw in Apache ActiveMQ Exposes Linux Systems to Kinsing Malware

The team also identified Ddostf, a malware strain with a track record dating back to 2016, which maintains its adeptness in executing precise Distributed Denial of Service (DDoS) attacks, including using the mentioned Apache flaw.

According to an advisory published by Fortinet on Tuesday, the severity of the situation is highlighted by the fact that despite a critical advisory from Apache and the issuance of a patch over a month ago, threat actors persist in exploiting CVE-2023-46604.

“Users should remain vigilant against ongoing exploits by Sliver, Kinsing, and Ddostf,” reads the technical write-up. “It is crucial to prioritize system updates and patching and regularly monitor security advisories to effectively mitigate the risk of exploitation.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/gotitan-botnet-prctrl-rat-exploit/