logo

Threat Actor Exploits Flaws and Uses Elastic Cloud SIEM to Manage Stolen Data

ID: 9d0c78df-3d07-5795-bfb7-a162a01c4994

STIX ID: report--9d0c78df-3d07-5795-bfb7-a162a01c4994

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

...
...

A threat actor abused vulnerabilities in enterprise software to deploy an encoded PowerShell script that collected detailed host and Active Directory data, then exfiltrated that data into an attacker-controlled Elastic Cloud SIEM trial instance (index "systeminfo"). Huntress identified telemetry showing administrative interactions via Kibana, registration via disposable emails tied to a temporary-email network, VPN-proxied logins, reuse of random identifiers and Cloudflare-hosted tooling; at least 216 hosts across 34 AD domains in government, education, finance, manufacturing, IT services and retail were indicated, and the Elastic instance has been taken offline after coordinated notification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.