Malware & Threats

DreamBus Botnet Exploiting RocketMQ Vulnerability to Delivery Cryptocurrency Miner

The DreamBus botnet has resurfaced and it has been exploiting a recently patched Apache RocketMQ vulnerability to deliver a Monero miner.

The DreamBus botnet has resurfaced and it has been exploiting a recently patched Apache RocketMQ vulnerability to deliver a Monero miner.

The DreamBus botnet has resurfaced after a two-year break and it has been seen exploiting a recently patched Apache RocketMQ vulnerability in attacks whose goal is the delivery of a cryptocurrency miner.

Apache RocketMQ is a widely used distributed messaging and streaming platform. The exploited vulnerability is tracked as CVE-2023-33246 and its existence came to light in late May, when RocketMQ version 5.1.1 was released to patch the issue. 

CVE-2023-33246 has been classified as ‘critical’ and it can be exploited by an unauthenticated attacker for remote command execution.

Details and proof-of-concept (PoC) exploits emerged in June, and reports of exploitation in the wild emerged shortly after. The ZoomEye cyberspace mapping service had recorded more than 6,000 traces of intrusion at the time — mainly in China — and the number has now gone up to 11,000. 

Juniper Networks reported this week that it started seeing attacks exploiting CVE-2023-33246 in early June, with a peak reached in mid-June, as part of activity associated with the DreamBus botnet. 

The first exploitation attempts were designed to look for vulnerable RocketMQ servers, but threat actors later started delivering a malicious bash script designed to download the main module of the DreamBus malware.

Advertisement. Scroll to continue reading.

This main module, which is an ELF Linux binary, has been packed with the UPX executable file compressor but in a way that makes the malware’s analysis more difficult.

DreamBus is a Linux malware that emerged in early 2019, but Juniper said it had not been seen since 2021, until now. 

The main goal in this case appears to be the distribution of a Monero cryptocurrency miner on infected systems. However, Juniper researchers said DreamBus can also attempt to spread to internal and external IP ranges. This worm-like behavior is not new for the malware. 

“As DreamBus malicious threat actors resurface, their primary objective remains the installation of a Monero cryptocurrency miner. However, the presence of a modular bot like the DreamBus malware equipped with the ability to execute bash scripts provides these cybercriminals the potential to diversify their attack repertoire, including the installation of various other forms of malware,” Juniper said.

Juniper provides indicators of compromise (IoCs) and recommendations for protecting systems against such attacks. 

Related: Qakbot Botnet Disrupted in Operation ‘Duck Hunt’

Related: Multiple DDoS Botnets Exploiting Recent Zyxel Vulnerability

Related: New ‘GoBruteforcer’ Botnet Targets Web Servers

Related Content

Vulnerabilities

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.

Cybercrime

An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026.

Malware & Threats

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign.

Malware & Threats

ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.

Vulnerabilities

CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.

Vulnerabilities

Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.

Malware & Threats

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

Vulnerabilities

CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version