Trusted Design

The Elastic Botnet

概要

Novetta has collected and shares within this report evidence that suggests multiple actors, possibly working independently while sharing information between themselves, are exploiting the Elasticsearch vulnerability primarily to establish widespread DDoS botnet infrastructures. Using both the Elknot and BillGates DDoS malware, these attackers have continued to infect vulnerable Elasticsearch servers in order to enhance their DDoS capabilities. The continuous scanning and exploitation of Elasticsearch servers is the most visible feature of these actors, and some actors have continued to infect and reinfect servers for weeks on end.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 16.27
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1091 - Replication Through Removable Media
  • T1126 - Network Share Connection Removal
  • T1003.003 - NTDS
  • T1008 - Fallback Channels
MITREへのリンク →

Sea Turtle

Score: 3.03
Matched TTPs:
  • T1033 - System Owner/User Discovery
MITREへのリンク →

Ember Bear

Score: 12.50
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1550 - Use Alternate Authentication Material
  • T1059.001 - PowerShell
  • T1003.003 - NTDS
MITREへのリンク →

Indrik Spider

Score: 5.87
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1546.016 - Installer Packages
MITREへのリンク →

Agrius

Score: 3.03
Matched TTPs:
  • T1033 - System Owner/User Discovery
MITREへのリンク →

Contagious Interview

Score: 12.98
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1091 - Replication Through Removable Media
  • T1021.006 - Windows Remote Management
  • T1126 - Network Share Connection Removal
MITREへのリンク →

Sandworm Team

Score: 19.84
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1686.003 - Windows Host Firewall
  • T1091 - Replication Through Removable Media
  • T1049 - System Network Connections Discovery
  • T1075 - Pass the Hash
  • T1546.016 - Installer Packages
MITREへのリンク →

Star Blizzard

Score: 5.01
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1091 - Replication Through Removable Media
MITREへのリンク →

Volt Typhoon

Score: 10.30
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1049 - System Network Connections Discovery
  • T1546.016 - Installer Packages
MITREへのリンク →

Storm-0501

Score: 3.84
Matched TTPs:
  • T1686.003 - Windows Host Firewall
MITREへのリンク →

HAFNIUM

Score: 7.47
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1049 - System Network Connections Discovery
MITREへのリンク →

APT5

Score: 3.84
Matched TTPs:
  • T1027.008 - Stripped Payloads
MITREへのリンク →

Ke3chang

Score: 6.44
Matched TTPs:
  • T1027.008 - Stripped Payloads
  • T1550 - Use Alternate Authentication Material
MITREへのリンク →

APT29

Score: 8.38
Matched TTPs:
  • T1202 - Indirect Command Execution
  • T1592.004 - Client Configurations
MITREへのリンク →

Earth Lusca

Score: 7.55
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1059.001 - PowerShell
  • T1546.016 - Installer Packages
MITREへのリンク →

Mustang Panda

Score: 10.64
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.001 - Local Account
  • T1055.005 - Thread Local Storage
MITREへのリンク →

LuminousMoth

Score: 4.57
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1550 - Use Alternate Authentication Material
MITREへのリンク →

Mustard Tempest

Score: 6.51
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1543.002 - Systemd Service
MITREへのリンク →

OilRig

Score: 6.51
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1592.002 - Software
MITREへのリンク →

Gamaredon Group

Score: 6.11
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1086 - PowerShell
MITREへのリンク →

Threat Group-3390

Score: 4.72
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1059.001 - PowerShell
MITREへのリンク →

BlackByte

Score: 4.57
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1550 - Use Alternate Authentication Material
MITREへのリンク →

APT32

Score: 8.41
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1550 - Use Alternate Authentication Material
  • T1592.004 - Client Configurations
MITREへのリンク →

Moonstone Sleet

Score: 5.82
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1126 - Network Share Connection Removal
MITREへのリンク →

FIN7

Score: 4.72
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1059.001 - PowerShell
MITREへのリンク →

Dragonfly

Score: 8.17
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1059.001 - PowerShell
  • T1546.016 - Installer Packages
MITREへのリンク →

Patchwork

Score: 5.88
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1008 - Fallback Channels
MITREへのリンク →

Axiom

Score: 6.21
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1049 - System Network Connections Discovery
MITREへのリンク →

Lazarus Group

Score: 13.69
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1546.016 - Installer Packages
  • T1055.005 - Thread Local Storage
  • T1086 - PowerShell
MITREへのリンク →

APT28

Score: 5.34
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1059.001 - PowerShell
MITREへのリンク →

menuPass

Score: 5.34
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1059.001 - PowerShell
MITREへのリンク →

Leviathan

Score: 5.43
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1546.016 - Installer Packages
MITREへのリンク →

UNC3886

Score: 4.13
Matched TTPs:
  • T1021.006 - Windows Remote Management
MITREへのリンク →

BRONZE BUTLER

Score: 7.13
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1008 - Fallback Channels
MITREへのリンク →

LAPSUS$

Score: 4.13
Matched TTPs:
  • T1557.002 - ARP Cache Poisoning
MITREへのリンク →

Scattered Spider

Score: 4.13
Matched TTPs:
  • T1557.002 - ARP Cache Poisoning
MITREへのリンク →

Rocke

Score: 3.29
Matched TTPs:
  • T1008 - Fallback Channels
MITREへのリンク →

APT41

Score: 3.29
Matched TTPs:
  • T1008 - Fallback Channels
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1008 - Fallback Channels
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Sandworm Team

Score: 0.83
Matched TTPs:
  • T1686.003 - Windows Host Firewall
  • T1033 - System Owner/User Discovery
  • T1091 - Replication Through Removable Media
  • T1075 - Pass the Hash
  • T1546.016 - Installer Packages
  • T1049 - System Network Connections Discovery
MITREへのリンク →

Kimsuky

Score: 0.66
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1008 - Fallback Channels
  • T1126 - Network Share Connection Removal
  • T1091 - Replication Through Removable Media
  • T1003.003 - NTDS
MITREへのリンク →

Lazarus Group

Score: 0.57
Matched TTPs:
  • T1055.005 - Thread Local Storage
  • T1086 - PowerShell
  • T1546.016 - Installer Packages
  • T1550 - Use Alternate Authentication Material
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る