“NightLion” Worm Strikes Again
ID: f8d00ff5-d28e-537a-be83-ea3afef18acd
STIX ID: report--f8d00ff5-d28e-537a-be83-ea3afef18acd
Feed Name: Cyble Blog
Cyble Research Labs observed a worm that automatically discovers unauthenticated Elasticsearch instances, deletes most indices, and places a readme demanding payment while blaming Night Lion Security/Shadow Byte; 829 open ES servers were identified as attacked between May 24 and June 23, 2022, with some indexes containing sensitive data up to ~10GB. The activity mirrors a 2020 campaign that similarly targeted thousands of ES servers, and the report advises enabling authentication, auditing internet-facing databases, and monitoring for misconfigurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
