rabbitmq-tactics
Audited by Socket on Aug 12, 2026
2 alerts found:
Malwarex2该技能是面向 AI 代理的 RabbitMQ 攻击与后渗透手册,核心功能包括弱口令攻击、消息窃取、外传、后门持久化、RCE 与痕迹规避。其真实能力与任何良性自动化帮助都不相称,应判定为恶意/高危技能。
This fragment is highly indicative of malicious intrusion/exfiltration and disruption against RabbitMQ. It describes authenticated Management API operations to configure persistent message forwarding to an attacker-controlled broker (Shovel/Federation), modify and republish message payloads (integrity compromise), purge/delete broker resources for DoS, and escalate using Erlang cookie-based remote command execution primitives (rpc/rabbitmqctl eval with os:cmd, including reverse-shell). If found inside any dependency/package, it should be treated as critical compromise material rather than legitimate software.