Attackers have actively exploited CVE-2023-46604, a remote code execution flaw in Apache ActiveMQ, to compromise Linux systems and install Kinsing (also known as h2miner). The vulnerability stems from improper validation of throwable class types in OpenWire commands during unmarshalling, allowing malicious code execution on exposed brokers. Trend Micro reported that intrusions led to the delivery of cryptocurrency-mining payloads and rootkit components, causing performance degradation and broader infrastructure impact.
Affected software includes multiple Apache ActiveMQ and Legacy OpenWire Module versions prior to the vendor’s patched releases. Apache addressed the issue by adding a validateIsThrowable check in the BaseDataStreamMarshall class, and organizations were urged to upgrade to 5.15.16, 5.16.7, 5.17.6, or 5.18.3 to block further exploitation and malware deployment.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Fortinet reported that attackers exploiting CVE-2023-46604 were deploying multiple malware families, including the newly identified Go-based botnet GoTitan, PrCtrl Rat, Sliver, Kinsing, and Ddostf. The report detailed an exploitation chain over ActiveMQ's OpenWire protocol that loads malicious XML from a remote URL to execute attacker-controlled code.
On November 3, 2023, Apache published an update describing CVE-2023-46604 as a remote code execution flaw in the Java OpenWire protocol marshaller affecting ActiveMQ brokers, ActiveMQ Artemis, and Java-based OpenWire clients. Apache advised upgrades and released fixed versions including ActiveMQ 6.0.0, 5.18.3, 5.17.6, 5.16.7, 5.15.16, and ActiveMQ Artemis 2.31.2.
The reference identifies fixed releases for affected Apache ActiveMQ and Legacy OpenWire Module versions and recommends upgrading to 5.15.16, 5.16.7, 5.17.6, or 5.18.3. The associated AMQ-9370 patch adds a validateIsThrowable method to BaseDataStreamMarshall.
The exploitation activity was observed leading to the download and installation of Kinsing (also known as h2miner) on vulnerable Linux systems, where it deploys cryptocurrency-mining payloads that degrade performance and damage infrastructure.
Trend Micro reported that attackers are actively exploiting CVE-2023-46604, a remote code execution vulnerability in Apache ActiveMQ caused by improper validation of throwable class types in OpenWire commands during unmarshalling.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
activemq.apache.org
Open sourcefortinet.com
Open sourcetrendmicro.com
Open sourceactivemq.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.