logo

A Threat Actor Abuses Another Free Trial

ID: 8b6374fe-8e39-5fd6-91f2-f5c4dc7baaee

STIX ID: report--8b6374fe-8e39-5fd6-91f2-f5c4dc7baaee

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2026-03-06

Date Updated: 2026-04-28

...
...

Huntress discovered a threat actor who exploited multiple vulnerabilities to compromise servers across dozens of organizations and exfiltrate system and Active Directory metadata (approx. 216 hosts spanning 34 domains) into a free Elastic Cloud SIEM trial; analysis of the Elastic deployment revealed attacker telemetry (disposable emails, Cloudflare worker subdomains, IPs linked to a SAFING_VPN, user-agent and host fingerprints) and active triage behavior, and Huntress coordinated with Elastic, other security teams, and law enforcement to notify victims and have the instance taken down.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.