Threat Actor Exploits Flaws and Uses Elastic Cloud SIEM to Manage Stolen Data
ID: 9d0c78df-3d07-5795-bfb7-a162a01c4994
STIX ID: report--9d0c78df-3d07-5795-bfb7-a162a01c4994
Feed Name: Infosecurity Magazine (News)
A threat actor abused vulnerabilities in enterprise software to deploy an encoded PowerShell script that collected detailed host and Active Directory data, then exfiltrated that data into an attacker-controlled Elastic Cloud SIEM trial instance (index "systeminfo"). Huntress identified telemetry showing administrative interactions via Kibana, registration via disposable emails tied to a temporary-email network, VPN-proxied logins, reuse of random identifiers and Cloudflare-hosted tooling; at least 216 hosts across 34 AD domains in government, education, finance, manufacturing, IT services and retail were indicated, and the Elastic instance has been taken offline after coordinated notification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
