#DripDropper
New malware called #DripDropper attacks Linux servers by exploiting an ActiveMQ vulnerability, then patches that vulnerability to lock out rival cybercriminals.

Read: hackread.com/dripdropper-...

#CyberSecurity #ActiveMQ #Vulnerability #Malware #Linux
New DripDropper Malware Exploits Linux Flaw Then Patches It Lock Rivals Out
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
August 20, 2025 at 1:44 PM
DripDropper #Linux malware cleans up after itself - how it works zdnet.com/article/drip... via @zdnet.bsky.social & @sjvn.bsky.social

An old #security hole is now being assaulted by an attack that patches the hole once it's in your computer.
DripDropper Linux malware cleans up after itself - how it works
This malware will still foul you up; it just doesn't want anyone messing with your servers while it's using you.
zdnet.com
August 19, 2025 at 1:57 PM
Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux #Systems

Threat actors are exploiting a nearly 2-year-old security flaw in #Apache ActiveMQ to gain persistent access to #cloud #Linux systems and deploy #malware called DripDropper!

#news
thehackernews.com/2025/08/apac...
Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems
Attackers exploit CVE-2023-46604 in Apache ActiveMQ, deploy DripDropper malware, then patch flaw to secure persistence.
thehackernews.com
August 19, 2025 at 9:48 PM
🟢 Hackers Patch Apache ActiveMQ Vulnerability After Breach

🗨️ Researchers from Red Canary report that hackers are using a new Linux malware called DripDropper. For these attacks,…

#news
Hackers Patch Apache ActiveMQ Vulnerability After Breach
Read more
hackmag.com
March 19, 2026 at 1:00 PM
‘DripDropper’ Hackers Patch Their Own Exploit

An attacker is breaking into Linux systems via a widely abused 2-year-old vulnerability in Apache ActiveMQ, installing malware and then patching the flaw.
‘DripDropper’ Hackers Patch Their Own Exploit
An attacker is breaking into Linux systems via a widely abused 2-year-old vulnerability in Apache ActiveMQ, installing malware and then patching the flaw.
www.darkreading.com
August 19, 2025 at 1:13 PM
📌 Sophisticated Attackers Exploit Two-Year-Old Apache ActiveMQ Flaw to Deploy DripDropper Malware on Linux Cloud Systems https://www.cyberhub.blog/article/12016-sophisticated-attackers-exploit-two-year-old-apache-activemq-flaw-to-deploy-dripdropper-malware-on-linux-cloud-systems
Sophisticated Attackers Exploit Two-Year-Old Apache ActiveMQ Flaw to Deploy DripDropper Malware on Linux Cloud Systems
A nearly two-year-old vulnerability in Apache ActiveMQ is being actively exploited by malicious actors to gain persistent access to Linux cloud systems and deploy a malware known as DripDropper. According to Red Canary, the attackers are employing a sophisticated tactic of patching the exploited vulnerability post-compromise to prevent other threat actors from gaining access and to evade detection. Apache ActiveMQ is a widely used open-source message broker that supports the Java Message Service (JMS) API. Vulnerabilities in such critical infrastructure components can have far-reaching implications, as they are often integral to enterprise messaging systems. The exploitation begins with the attackers leveraging the unpatched vulnerability in Apache ActiveMQ to gain initial access to the target systems. Once inside, they deploy DripDropper, a malware whose exact capabilities are not yet fully disclosed but is likely designed for persistence and potentially further payload delivery. What sets this campaign apart is the attackers' post-exploitation behavior. By patching the vulnerability they exploited, they ensure that no other malicious actors can use the same entry point, thereby maintaining exclusive control over the compromised systems. This tactic also helps them avoid detection, as the patched vulnerability might not trigger any alerts from security monitoring tools. The impact of this campaign could be significant, particularly if the targeted systems are part of critical infrastructure or handle sensitive data. The sophistication demonstrated by the attackers in patching the vulnerability post-exploitation indicates a high level of operational security (OPSEC) awareness. For organizations using Apache ActiveMQ, it is crucial to ensure that all systems are updated with the latest security patches. Additionally, monitoring for unusual activities such as unauthorized access or unexpected patching of vulnerabilities can help detect potential compromises. This incident underscores the importance of timely patch management and the need for continuous monitoring of enterprise systems. It also highlights the evolving tactics of threat actors, who are increasingly adopting measures to maintain exclusivity and avoid detection.
www.cyberhub.blog
August 19, 2025 at 9:00 PM
Patching for persistence: How DripDropper Linux malware moves through the cloud - " an adversary exploiting CVE-2023-46604 in Apache ActiveMQ to gain persistent access on cloud Linux systems, patching the exploited vulnerability after securing initial access to secure their foothold"
Patching for persistence: How DripDropper Linux malware moves through the cloud - " an adversary exploiting CVE-2023-46604 in Apache ActiveMQ to gain persistent access on cloud Linux systems, patching the exploited vulnerability after securing initial access to secure their foothold"
redcanary.com
August 20, 2025 at 8:39 PM
‘DripDropper’ Hackers Patch Their Own ActiveMQ Exploit 

This I have to admit is a new one. Security researchers detected an attacker exploiting Apache ActiveMQ, a popular open-source message broker, a security hole that is detailed in CVE-2023-46604, to gain persistent access on cloud…
‘DripDropper’ Hackers Patch Their Own ActiveMQ Exploit 
This I have to admit is a new one. Security researchers detected an attacker exploiting Apache ActiveMQ, a popular open-source message broker, a security hole that is detailed in CVE-2023-46604, to gain persistent access on cloud Linux systems. The new part is that the attacker is apparently patching the vulnerability after securing initial access to secure their foothold and evade detection as per this: 
itnerd.blog
August 20, 2025 at 12:35 PM
Red Canary alerte sur DripDropper, un malware visant les systèmes Linux
Red Canary alerte sur DripDropper, un malware visant les systèmes Linux - INCYBER NEWS
Après avoir pris le contrôle de l'appareil en exploitant une vulnérabilité, le logiciel malveillant corrige cette faille.
incyber.org
August 25, 2025 at 7:12 PM
Patching for persistence: How DripDropper Linux malware moves through the cloud
Patching for persistence: How DripDropper Linux malware moves through the cloud | Red Canary
DripDropper is a Red Canary-named Linux malware variant that uses an encrypted PyInstaller ELF file to communicate with a Dropbox account.
redcanary.com
August 19, 2025 at 5:28 PM
'DripDropper' Hackers Patch Their Own Exploit
'DripDropper' Hackers Patch Their Own Exploit
An attacker is breaking into Linux systems via a widely abused 2-year-old vulnerability in Apache ActiveMQ, installing malware and then patching the flaw.
www.darkreading.com
August 19, 2025 at 1:18 PM
DripDropper Malware: When Hackers Become Security Patchers

In an unprecedented display of cybercriminal sophistication, security researchers have uncovered a Linux malware campaign that turns conventional attack methodology on its head. The malware, dubbed "DripDropper," employs a counterintuitive…
DripDropper Malware: When Hackers Become Security Patchers
In an unprecedented display of cybercriminal sophistication, security researchers have uncovered a Linux malware campaign that turns conventional attack methodology on its head. The malware, dubbed "DripDropper," employs a counterintuitive strategy: exploiting vulnerabilities and then patching them to maintain exclusive access to compromised systems.
www.spartechsoftware.com
August 20, 2025 at 3:55 PM
DripDropper #Linux malware cleans up after itself - how it works

This malware will still foul you up; it just doesn't want anyone messing with your servers while it's using you.
DripDropper Linux malware cleans up after itself - how it works
This malware will still foul you up; it just doesn't want anyone messing with your servers while it's using you.
www.zdnet.com
August 28, 2025 at 10:13 AM
Quando i Criminal Hacker patchano al posto tuo i server Linux! E non è cosa buona
Gli specialisti di Red Canary hanno scoperto un’insolita campagna che utilizza il nuovo malware DripDropper,...
Quando i Criminal Hacker patchano al posto tuo i server Linux! E non è cosa buona
www.redhotcyber.com
August 20, 2025 at 8:45 AM
Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems
Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and deploy malware called DripDropper.
Link Preview
Visit the link for more information
thehackernews.com
August 19, 2025 at 6:05 PM
🧨 Another week, another “old” vuln under active exploitation:

"Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems" - The Hacker News

CVE-2023-46604 in Apache ActiveMQ isn’t new - but attackers still use it to get RCE through a single, unauthenticated request.

⬇️ ⬇️
August 27, 2025 at 6:39 AM
Threat Actors Exploit Two-Year-Old Apache ActiveMQ Flaw to Deploy DripDropper Malware on Linux Systems Threat Actors Exploit Two-Year-Old Apache ActiveMQ Flaw to Deploy DripDropper Malware on Linux...

#News

Origin | Interest | Match
September 3, 2025 at 8:26 AM
Threat Actors Exploit Two-Year-Old Apache ActiveMQ Flaw to Deploy DripDropper Malware on Linux Systems Threat Actors Exploit Two-Year-Old Apache ActiveMQ Flaw to Deploy DripDropper Malware on Linux...

#News

Origin | Interest | Match
September 1, 2025 at 2:32 PM