Malicious ActiveMQ Exploitation Java Spawning PowerShell Downloader (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-06
Updated
2026-09-06

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule detects an ActiveMQ Java process spawning PowerShell that downloads a remote payload. Exploitation of CVE-2023-46604 caused the ActiveMQ java process to launch PowerShell IEX and DownloadFile commands to stage ransomware.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious Cleo Autorun Health Check File Drop (via file_event)
Obfuscated IIS Worker Spawning Encoded PowerShell after SharePoint ToolShell (via process_creation)
Malicious In-Memory Payload Execution via PowerShell DownloadString (via process_creation)
Suspicious Remote Script Download and Execution via iwr Piped to iex
Malicious WSUS Service Spawning Command Shell via Remote Code Execution
Suspicious PowerShell Invoke-WebRequest Download of Executable Payload
Malicious PowerShell Spawned by IIS Worker Process via OWASSRF Exchange Exploitation (via process_creation)
Suspicious Hidden PowerShell Download and Archive Expansion
Malicious PowerShell IEX DownloadString One-Liner
Malicious ActiveMQ Exploitation Java Spawning PowerShell Downloader (via process_creation)
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.