DripDropper is a Linux malware family identified by Red Canary and described as a previously unknown downloader/backdoor used in intrusions against cloud-hosted Linux systems. It has been observed after exploitation of Apache ActiveMQ CVE-2023-46604, a remote code execution vulnerability, to gain persistent access on vulnerable servers. The malware was deployed by unknown threat actors in campaigns targeting cloud Linux environments running ActiveMQ.
DripDropper is described as an encrypted, password-protected PyInstaller ELF executable that communicates with an attacker-controlled Dropbox account using a hardcoded bearer token. It commonly drops two additional malicious files. One dropped file may perform process monitoring or retrieve follow-up instructions from Dropbox, with its name and location determined by execution arguments. Persistence for this component was established by modifying 0anacron files across /etc/cron.* directories. The second dropped file uses a randomly generated eight-character alphabetical filename, also contacts Dropbox for commands, modifies SSH-related configuration files, and changes the default login shell for the games user account to /bin/sh, likely to support persistent shell-based access.
Associated post-exploitation activity in the same intrusion cluster included use of Sliver and Cloudflare Tunnels for command and control, and modification of sshd configuration to enable root login over SSH. A notable behavior linked to these intrusions is that the operators downloaded legitimate patched ActiveMQ JARs from repo1[.]maven[.]org / Apache Maven and replaced vulnerable JAR files, effectively patching CVE-2023-46604 on already-compromised hosts. Red Canary assessed this was done to prevent competing attackers from exploiting the same flaw and to reduce detection by vulnerability scanners. High-confidence indicators and behaviors mentioned in the content include Dropbox-based communications via a hardcoded token, creation of two secondary files, cron/0anacron persistence, SSH configuration changes, root SSH enablement, and modification of the games account shell to /bin/sh.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Under a new session started by sshd, the adversary downloaded and executed a previously unknown downloader that we have named “DripDropper.”
11 distinct techniques documented for this family, organized by ATT&CK tactic.
DripDropper will establish persistent execution for the dropped file by modifying the 0anacron file observed in each /etc/cron.*/ directory.
Under these new settings, the attacker finally drops and executes DripDropper. This is an encrypted PyInstaller ELF binary requiring a password to run. This approach makes reverse engineering difficult.
Needless to say, once in, DripDropper deploys Command and Control (C2) frameworks such as Sliver and Cloudflare Tunnels for long-term control.
It communicates with an adversary-controlled Dropbox account using a hardcoded bearer token.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux malware payload reportedly dropped by unknown actors through exploitation of an Apache ActiveMQ vulnerability.
Malware deployed on cloud Linux systems after exploiting Apache ActiveMQ; used to maintain access/persistence (per summary).
Malware deployed on cloud Linux systems after exploitation of an Apache ActiveMQ flaw; attackers reportedly patch the exploited vuln post-compromise to block other actors (per excerpt).
Malware/loader referenced in connection with exploitation of Apache ActiveMQ (CVE-2023-46604) to compromise cloud-hosted Linux servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.