Make a Living ClubMake a Living Club
  • Home
  • News
  • Business
  • Finance
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • More
    • Economy
    • Politics
    • Real Estate
Trending Now

John Wiley & Sons, Inc. (WLY) Q2 2026 Earnings Call Transcript

December 4, 2025

General Motors Company (GM) Presents at UBS Global Industrials and Transportation Conference Transcript

December 3, 2025

Verizon: Not A Value Trap, The Math Works (NYSE:VZ)

December 2, 2025

John Hancock Multimanager 2015 Lifetime Portfolio Q3 2025 Commentary

December 1, 2025

BitMine Immersion: Major Test Passed So Far (NYSE:BMNR)

November 30, 2025

United Natural Foods Q1 Preview: Doesn’t Seem Like An Exciting Opportunity Right Now

November 28, 2025
Facebook Twitter Instagram
  • Privacy
  • Terms
  • Press
  • Advertise
  • Contact
Facebook Twitter Instagram
Make a Living ClubMake a Living Club
  • Home
  • News
  • Business
  • Finance
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • More
    • Economy
    • Politics
    • Real Estate
Sign Up for News & Alerts
Make a Living ClubMake a Living Club
Home » Hackers Exploit Apache ActiveMQ Flaw To Mine Crypto
Crypto

Hackers Exploit Apache ActiveMQ Flaw To Mine Crypto

Press RoomBy Press RoomNovember 22, 2023
Facebook Twitter Pinterest LinkedIn WhatsApp Email
Source: Pixabay

Hackers are currently targeting a critical Apache ActiveMQ vulnerability to download and infect Linux machines with the Kinsing malware and crypto miner.

In a blog post published on November 20, Trend Micro researchers reported that the exploitation of the CVE-2023-46604 vulnerability in the open-source ActiveMQ protocol results in remote code execution (RCE), which allows Kinsing to carry out the download and installation of malware.

Following a system infection, Kinsing deploys a cryptocurrency-mining script that exploits the host’s resources to mine cryptocurrencies such as Bitcoin. This not only leads to substantial damage to infrastructure but also adversely affects system performance.

The Kinsing malware poses a significant threat, focusing primarily on Linux-based systems, the researchers added. This malicious software has the capability to infiltrate servers and spread rapidly throughout a network. Its mode of entry involves exploiting vulnerabilities present in web applications or misconfigured container environments.

“Organizations that use Apache ActiveMQ must take immediate action to patch CVE-2023-46604 as soon as possible and mitigate the risks associated with Kinsing,” the researchers said in the post. “Given the malware’s ability to spread across networks and exploit multiple vulnerabilities, it is important to maintain up-to-date security patches, regularly audit configurations, and monitor network traffic for unusual activity, all of which are critical components of a comprehensive cybersecurity strategy.”

The vulnerability’s root cause lies in a problem related to the validation of throwable class types during the unmarshalling of OpenWire commands, the researchers noted.

Reports emerged earlier this month regarding the active exploitation of CVE-2023-46604, with hackers utilizing exploits like Metasploit and Nuclei. Despite the high severity of the vulnerability, rated at CVSS 9.8, the level of detection remains comparatively low.

John Gallagher, vice president of Viakoo Labs, highlighted the significance of the CVE, emphasizing the widespread use of Apache ActiveMQ and its ability to communicate across multiple protocols. Additionally, he pointed out its extensive utilization in non-IT environments for interfacing with IoT/OT/ICS devices.

Gallagher further noted that many organizations face challenges in maintaining the patching of IoT devices. Given this scenario, Kinsing’s strategic choice to exploit this vulnerability aligns well with their objective of sustained processing, particularly for activities such as cryptomining.

“Many IoT devices have powerful processing capabilities and lack patching policies, making mining an ideal activity for them,” said Gallagher. “To put it another way, Kinsing likely chose to use this CVE for crypto mining because they expect it to be a long-lived vulnerability; it wouldn’t make any sense if it was a vulnerability Kinsing was expecting to get patched quickly.”


Enter your email for our Free Daily Newsletter

A quick 3min read about today’s crypto news!

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

'Fundamental Shift' in Traditional Bitcoin Market Cycle May Be on the Horizon

Crypto October 3, 2024

FTX/Alameda Unstakes Over $1B in Solana – Is a Major Price Shift Coming?

Crypto September 14, 2024

Blockchain News

Crypto May 30, 2024

Crypto Whales Are Stockpiling This New Dog Coin – Is It the Next Dogecoin?

Crypto May 29, 2024

Shiba Inu Price Prediction as Investor Turns $2,625 into $1.1 Million – Another Major Rally Starting?

Crypto May 28, 2024

Crypto Experts Pile Into New Solana Project – Could It Be the Next Big Thing?

Crypto May 27, 2024
Add A Comment

Leave A Reply Cancel Reply

Latest News

General Motors Company (GM) Presents at UBS Global Industrials and Transportation Conference Transcript

December 3, 2025

Verizon: Not A Value Trap, The Math Works (NYSE:VZ)

December 2, 2025

John Hancock Multimanager 2015 Lifetime Portfolio Q3 2025 Commentary

December 1, 2025

BitMine Immersion: Major Test Passed So Far (NYSE:BMNR)

November 30, 2025

United Natural Foods Q1 Preview: Doesn’t Seem Like An Exciting Opportunity Right Now

November 28, 2025
Trending Now

The housing crisis is pushing Gen Z into crypto and economic nihilism

November 28, 2025

Voya Infrastructure, Industrials And Materials Fund Q3 2025 Commentary

November 27, 2025

Banco BBVA Argentina S.A. (BBAR) Q3 2025 Earnings Call Transcript

November 26, 2025

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Make a Living is your one-stop news website for the latest personal finance, investing and markets news and updates, follow us now to get the news that matters to you.

We're social. Connect with us:

Facebook Twitter Instagram YouTube LinkedIn
Topics
  • Business
  • Economy
  • Finance
  • Investing
  • Markets
Quick Links
  • Cookie Policy
  • Advertise with us
  • Get in touch
  • Submit News
  • Newsletter

Subscribe to Updates

Get the latest finance, markets, and business news and updates directly to your inbox.

2025 © Make a Living Club. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.