The Elastic Botnet
概要
Novetta has collected and shares within this report evidence that suggests multiple actors,
possibly working independently while sharing information between themselves, are exploiting the Elasticsearch vulnerability primarily to establish widespread DDoS botnet infrastructures. Using both the Elknot and BillGates DDoS malware, these attackers have continued to infect vulnerable Elasticsearch servers in order to enhance their DDoS capabilities. The continuous scanning and exploitation of Elasticsearch servers is the most visible feature of these actors, and some actors have continued to infect and reinfect servers for weeks on end.
Created: 2026-02-23
Indicators
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 16.27
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1091 - Replication Through Removable Media
- T1126 - Network Share Connection Removal
- T1003.003 - NTDS
- T1008 - Fallback Channels
MITREへのリンク →
Score: 3.03
Matched TTPs:
- T1033 - System Owner/User Discovery
MITREへのリンク →
Score: 12.50
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1550 - Use Alternate Authentication Material
- T1059.001 - PowerShell
- T1003.003 - NTDS
MITREへのリンク →
Score: 5.87
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1546.016 - Installer Packages
MITREへのリンク →
Score: 3.03
Matched TTPs:
- T1033 - System Owner/User Discovery
MITREへのリンク →
Score: 12.98
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1091 - Replication Through Removable Media
- T1021.006 - Windows Remote Management
- T1126 - Network Share Connection Removal
MITREへのリンク →
Score: 19.84
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1686.003 - Windows Host Firewall
- T1091 - Replication Through Removable Media
- T1049 - System Network Connections Discovery
- T1075 - Pass the Hash
- T1546.016 - Installer Packages
MITREへのリンク →
Score: 5.01
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1091 - Replication Through Removable Media
MITREへのリンク →
Score: 10.30
Matched TTPs:
- T1686.003 - Windows Host Firewall
- T1049 - System Network Connections Discovery
- T1546.016 - Installer Packages
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1686.003 - Windows Host Firewall
MITREへのリンク →
Score: 7.47
Matched TTPs:
- T1027.008 - Stripped Payloads
- T1049 - System Network Connections Discovery
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1027.008 - Stripped Payloads
MITREへのリンク →
Score: 6.44
Matched TTPs:
- T1027.008 - Stripped Payloads
- T1550 - Use Alternate Authentication Material
MITREへのリンク →
Score: 8.38
Matched TTPs:
- T1202 - Indirect Command Execution
- T1592.004 - Client Configurations
MITREへのリンク →
Score: 7.55
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1059.001 - PowerShell
- T1546.016 - Installer Packages
MITREへのリンク →
Score: 10.64
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1136.001 - Local Account
- T1055.005 - Thread Local Storage
MITREへのリンク →
Score: 4.57
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1550 - Use Alternate Authentication Material
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1543.002 - Systemd Service
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1592.002 - Software
MITREへのリンク →
Score: 6.11
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1086 - PowerShell
MITREへのリンク →
Score: 4.72
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1059.001 - PowerShell
MITREへのリンク →
Score: 4.57
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1550 - Use Alternate Authentication Material
MITREへのリンク →
Score: 8.41
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1550 - Use Alternate Authentication Material
- T1592.004 - Client Configurations
MITREへのリンク →
Score: 5.82
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1126 - Network Share Connection Removal
MITREへのリンク →
Score: 4.72
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1059.001 - PowerShell
MITREへのリンク →
Score: 8.17
Matched TTPs:
- T1550 - Use Alternate Authentication Material
- T1059.001 - PowerShell
- T1546.016 - Installer Packages
MITREへのリンク →
Score: 5.88
Matched TTPs:
- T1550 - Use Alternate Authentication Material
- T1008 - Fallback Channels
MITREへのリンク →
Score: 6.21
Matched TTPs:
- T1550 - Use Alternate Authentication Material
- T1049 - System Network Connections Discovery
MITREへのリンク →
Score: 13.69
Matched TTPs:
- T1550 - Use Alternate Authentication Material
- T1546.016 - Installer Packages
- T1055.005 - Thread Local Storage
- T1086 - PowerShell
MITREへのリンク →
Score: 5.34
Matched TTPs:
- T1550 - Use Alternate Authentication Material
- T1059.001 - PowerShell
MITREへのリンク →
Score: 5.34
Matched TTPs:
- T1550 - Use Alternate Authentication Material
- T1059.001 - PowerShell
MITREへのリンク →
Score: 5.43
Matched TTPs:
- T1550 - Use Alternate Authentication Material
- T1546.016 - Installer Packages
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1021.006 - Windows Remote Management
MITREへのリンク →
Score: 7.13
Matched TTPs:
- T1592.004 - Client Configurations
- T1008 - Fallback Channels
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1557.002 - ARP Cache Poisoning
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1557.002 - ARP Cache Poisoning
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1008 - Fallback Channels
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1008 - Fallback Channels
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1008 - Fallback Channels
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.83
Matched TTPs:
- T1686.003 - Windows Host Firewall
- T1033 - System Owner/User Discovery
- T1091 - Replication Through Removable Media
- T1075 - Pass the Hash
- T1546.016 - Installer Packages
- T1049 - System Network Connections Discovery
MITREへのリンク →
Score: 0.66
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1008 - Fallback Channels
- T1126 - Network Share Connection Removal
- T1091 - Replication Through Removable Media
- T1003.003 - NTDS
MITREへのリンク →
Score: 0.57
Matched TTPs:
- T1055.005 - Thread Local Storage
- T1086 - PowerShell
- T1546.016 - Installer Packages
- T1550 - Use Alternate Authentication Material
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る