logo

“NightLion” Worm Strikes Again

ID: f8d00ff5-d28e-537a-be83-ea3afef18acd

STIX ID: report--f8d00ff5-d28e-537a-be83-ea3afef18acd

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-11-27

Date Updated: 2026-07-16

...
...

Cyble Research Labs observed a worm that automatically discovers unauthenticated Elasticsearch instances, deletes most indices, and places a readme demanding payment while blaming Night Lion Security/Shadow Byte; 829 open ES servers were identified as attacked between May 24 and June 23, 2022, with some indexes containing sensitive data up to ~10GB. The activity mirrors a 2020 campaign that similarly targeted thousands of ES servers, and the report advises enabling authentication, auditing internet-facing databases, and monitoring for misconfigurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.