TellYouThePass is a ransomware threat actor known for exploiting public-facing vulnerabilities for rapid initial access and malware deployment. The group has been publicly linked to zero-day exploitation of CVE-2023-46604 in Apache ActiveMQ, demonstrating opportunistic use of newly disclosed or previously unpatched enterprise software flaws to gain code execution on exposed systems. TellYouThePass has been identified among multiple threat groups abusing Apache ActiveMQ vulnerabilities to distribute ransomware and other malicious payloads. Available reporting directly supports TellYouThePass as a ransomware operator, but does not provide high-confidence attribution to a specific country, nor a detailed victimology profile by geography or sector. Based on the confirmed exploitation activity, the actor demonstrates initial-access capability through vulnerability exploitation and post-compromise deployment of ransomware for financial gain. No additional aliases, sub-groups, or extortion tradecraft are directly supported by the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used CVE-2023-46604 in Apache ActiveMQ as a zero-day flaw in attacks.
Conducted ransomware activity targeting Apache ActiveMQ by exploiting CVE-2023-46604 as a zero-day.
Referenced as a threat group previously exploiting CVE-2023-46604 in Apache ActiveMQ to spread ransomware and other malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.