Trusted Design

The Elastic Botnet

概要

Novetta has collected and shares within this report evidence that suggests multiple actors, possibly working independently while sharing information between themselves, are exploiting the Elasticsearch vulnerability primarily to establish widespread DDoS botnet infrastructures. Using both the Elknot and BillGates DDoS malware, these attackers have continued to infect vulnerable Elasticsearch servers in order to enhance their DDoS capabilities. The continuous scanning and exploitation of Elasticsearch servers is the most visible feature of these actors, and some actors have continued to infect and reinfect servers for weeks on end.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 16.27
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1587 - Develop Capabilities
  • T1588.005 - Exploits
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Sea Turtle

Score: 3.03
Matched TTPs:
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Ember Bear

Score: 12.50
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1560 - Archive Collected Data
  • T1210 - Exploitation of Remote Services
  • T1588.005 - Exploits
MITREへのリンク →

Indrik Spider

Score: 5.87
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1584.004 - Server
MITREへのリンク →

Agrius

Score: 3.03
Matched TTPs:
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Contagious Interview

Score: 12.98
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
  • T1681 - Search Threat Vendor Data
  • T1587 - Develop Capabilities
MITREへのリンク →

Sandworm Team

Score: 19.84
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1588.006 - Vulnerabilities
  • T1608.001 - Upload Malware
  • T1584.005 - Botnet
  • T1499 - Endpoint Denial of Service
  • T1584.004 - Server
MITREへのリンク →

Star Blizzard

Score: 5.01
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
MITREへのリンク →

Volt Typhoon

Score: 10.30
Matched TTPs:
  • T1588.006 - Vulnerabilities
  • T1584.005 - Botnet
  • T1584.004 - Server
MITREへのリンク →

Storm-0501

Score: 3.84
Matched TTPs:
  • T1588.006 - Vulnerabilities
MITREへのリンク →

HAFNIUM

Score: 7.47
Matched TTPs:
  • T1583.005 - Botnet
  • T1584.005 - Botnet
MITREへのリンク →

APT5

Score: 3.84
Matched TTPs:
  • T1583.005 - Botnet
MITREへのリンク →

Ke3chang

Score: 6.44
Matched TTPs:
  • T1583.005 - Botnet
  • T1560 - Archive Collected Data
MITREへのリンク →

APT29

Score: 8.38
Matched TTPs:
  • T1586.003 - Cloud Accounts
  • T1550.003 - Pass the Ticket
MITREへのリンク →

Earth Lusca

Score: 7.55
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1210 - Exploitation of Remote Services
  • T1584.004 - Server
MITREへのリンク →

Mustang Panda

Score: 10.64
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1176.002 - IDE Extensions
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

LuminousMoth

Score: 4.57
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1560 - Archive Collected Data
MITREへのリンク →

Mustard Tempest

Score: 6.51
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1608.006 - SEO Poisoning
MITREへのリンク →

OilRig

Score: 6.51
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1137.004 - Outlook Home Page
MITREへのリンク →

Gamaredon Group

Score: 6.11
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1561.001 - Disk Content Wipe
MITREへのリンク →

Threat Group-3390

Score: 4.72
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1210 - Exploitation of Remote Services
MITREへのリンク →

BlackByte

Score: 4.57
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1560 - Archive Collected Data
MITREへのリンク →

APT32

Score: 8.41
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1560 - Archive Collected Data
  • T1550.003 - Pass the Ticket
MITREへのリンク →

Moonstone Sleet

Score: 5.82
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1587 - Develop Capabilities
MITREへのリンク →

FIN7

Score: 4.72
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1210 - Exploitation of Remote Services
MITREへのリンク →

Dragonfly

Score: 8.17
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1210 - Exploitation of Remote Services
  • T1584.004 - Server
MITREへのリンク →

Patchwork

Score: 5.88
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Axiom

Score: 6.21
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1584.005 - Botnet
MITREへのリンク →

Lazarus Group

Score: 13.69
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1584.004 - Server
  • T1027.007 - Dynamic API Resolution
  • T1561.001 - Disk Content Wipe
MITREへのリンク →

APT28

Score: 5.34
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1210 - Exploitation of Remote Services
MITREへのリンク →

menuPass

Score: 5.34
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1210 - Exploitation of Remote Services
MITREへのリンク →

Leviathan

Score: 5.43
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1584.004 - Server
MITREへのリンク →

UNC3886

Score: 4.13
Matched TTPs:
  • T1681 - Search Threat Vendor Data
MITREへのリンク →

BRONZE BUTLER

Score: 7.13
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

LAPSUS$

Score: 4.13
Matched TTPs:
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Scattered Spider

Score: 4.13
Matched TTPs:
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Rocke

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

APT41

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.83
Matched TTPs:
  • T1588.006 - Vulnerabilities
  • T1499 - Endpoint Denial of Service
  • T1608.001 - Upload Malware
  • T1584.004 - Server
  • T1584.005 - Botnet
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Kimsuky

Score: 0.66
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.005 - Exploits
  • T1587 - Develop Capabilities
  • T1102.001 - Dead Drop Resolver
  • T1583 - Acquire Infrastructure
MITREへのリンク →

Lazarus Group

Score: 0.57
Matched TTPs:
  • T1561.001 - Disk Content Wipe
  • T1027.007 - Dynamic API Resolution
  • T1584.004 - Server
  • T1560 - Archive Collected Data
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る