elastic-logo.svg
  • Platform
  • Use cases
  • Pricing
  • Customers
  • Resources
  • Company
logo-cloud-32-color.svg
Elastic Cloud
Maximize value and optimize your experience

Deploy everything Elastic has to offer across any cloud, in minutes.

Learn more

    Additional Resources
  • icon-price-16-blue.svgView pricing
  • icon-download-16-blue.svgFree trial and downloads
  • icon-integration-16-blue.svgView all integrations
Use Elastic For
  • logo-enterprise-search-32-color.svg
    Enterprise Search

    Search and discovery experiences

  • logo-observability-32-color.svg
    Observability

    Unified logs, metrics, and traces

  • logo-security-32-color.svg
    Security

    SIEM, endpoint, and cloud

  • logo-cloud-32-color.svg
    Elastic Cloud

    Deploy and scale in any cloud

  • logo-stack-32-color.svg
    Elastic (ELK) Stack

    Elasticsearch, Kibana, and integrations

View platform overview
What's New
  • Elastic 8.6 released

    See the latest enhancements

  • Upgrade the Elastic Stack

    Expert tips when upgrading

  • Documentation

    Read latest product guides

  • ElasticON Global 2023

    Register now for free

  • We're hiring

    Join a global, distributed team

  • By Topic
    • Power of Elastic
    • Improving digital customer experiences
    • Evolving the DevOps lifecycle
    • Security without limits
    View all topics
  • By Industry
    • Public Sector
    • Financial Services
    • Telecommunications
    • Healthcare
    • Technology
    • Retail and Ecommerce
    • Media and Entertainment
    • Manufacturing and Automotive
    View all industries
  • Featured
    SIEM buyer's guide for the modern SOC

    Key considerations for evaluating and selecting a SIEM solution

    Download the guide

Stories By Use Case
  • Enterprise Search

    Search applications of all kinds

  • Observability

    Logs, metrics, APM, and more

  • Security

    SIEM, endpoint, cloud, and XDR

Help Center
  • Getting started

    Guidance to get started

  • Support

    Get help and customer resources

  • Contact us

    Have questions? Get in touch

Featured Customers
  • logo-nav-dropdown-48x48-jaguar.png
    Jaguar Land Rover

    Vehicle intelligence

  • logo-nav-dropdown-48x48-emirates-nbd.png
    Emirates NBD

    Secured billions in assets

  • logo-nav-dropdown-48x48-zurich.png
    Zurich Insurance

    Increased customer trust

View all case studies

Learn
  • Documentation

    Product guides

  • Blogs

    Tech topics, innovation, news

  • Training

    Skill building and certification

Engage
  • Events

    ElasticON, meetups, virtual events

  • Community

    Groups, forums, code

  • Consulting

    Outcome-based services

Featured
  • icon-blog-pencil-32-color.svg
    Driving quantified success with Elastic Enterprise Search
  • icon-training-on-demand-32-color.svg
    Get started with Elasticsearch
  • icon-certificate-award-32-color.svg
    Observability Engineer training

View all resources

  • About Elastic
    • About

      Our story and leadership

    • Careers

      Peruse our opportunities

    • Press

      Elastic news

    • Partners

      Find or become a partner

    • Investor Relations

      Results, filings, resources

    • Elastic Excellence Awards

      See remarkable work

  • Featured
    Why now is the time to move critical databases to the cloud

    Read more

ContactLogin
Try freeicon-magnifying-glass-24-blue.svg
elastic-logo.svg
icon-magnifying-glass-24-blue.svgicon-magnifying-glass-24-blue.svg
  • Platform
  • Use cases
  • Pricing
  • Customers
  • Resources
  • Company
Platform
Featured
  • logo-cloud-32-color.svgElastic Cloud
  • icon-price-16-blue.svgView pricing
  • icon-download-16-blue.svgFree trial and downloads
  • icon-integration-16-blue.svgView all integrations
Use Elastic For
  • logo-enterprise-search-32-color.svg
    Enterprise Search

    Search and discovery experiences

  • logo-observability-32-color.svg
    Observability

    Unified logs, metrics, and traces

  • logo-security-32-color.svg
    Security

    SIEM, endpoint, and cloud

  • logo-cloud-32-color.svg
    Elastic Cloud

    Deploy and scale in any cloud

  • logo-stack-32-color.svg
    Elastic (ELK) Stack

    Elasticsearch, Kibana, and integrations

View platform overview
What's New
  • Elastic 8.6 released

    See the latest enhancements

  • Upgrade the Elastic Stack

    Expert tips when upgrading

  • Documentation

    Read latest product guides

  • ElasticON Global 2023

    Register now for free

  • We're hiring

    Join a global, distributed team

Use cases
By Topic
Power of Elastic
Improving digital customer experiences
Evolving the DevOps lifecycle
Security without limits
View all topics
By Industry
Public Sector
Financial Services
Telecommunications
Healthcare
Technology
Retail and Ecommerce
Media and Entertainment
Manufacturing and Automotive
View all industries
FeaturedSIEM buyer's guide for the modern SOC
Customers
Stories By Use Case
  • Enterprise Search

    Search applications of all kinds

  • Observability

    Logs, metrics, APM, and more

  • Security

    SIEM, endpoint, cloud, and XDR

Help Center
  • Getting started

    Guidance to get started

  • Support

    Get help and customer resources

  • Contact us

    Have questions? Get in touch

Featured Customers
  • logo-nav-dropdown-48x48-jaguar.png
    Jaguar Land Rover

    Vehicle intelligence

  • logo-nav-dropdown-48x48-emirates-nbd.png
    Emirates NBD

    Secured billions in assets

  • logo-nav-dropdown-48x48-zurich.png
    Zurich Insurance

    Increased customer trust

View all case studies

Resources
Learn
  • Documentation

    Product guides

  • Blogs

    Tech topics, innovation, news

  • Training

    Skill building and certification

Engage
  • Events

    ElasticON, meetups, virtual events

  • Community

    Groups, forums, code

  • Consulting

    Outcome-based services

Featured
  • icon-blog-pencil-32-color.svg
    Driving quantified success with Elastic Enterprise Search
  • icon-training-on-demand-32-color.svg
    Get started with Elasticsearch
  • icon-certificate-award-32-color.svg
    Observability Engineer training

View all resources

Company
About Elastic
About

Our story and leadership

Careers

Peruse our opportunities

Press

Elastic news

Partners

Find or become a partner

Investor Relations

Results, filings, resources

Elastic Excellence Awards

See remarkable work

FeaturedWhy now is the time to move critical databases to the cloud
Try free

Have questions?

Contact us

Already have an account?

Log in
Security Labs
    About
    Topics
    • Security Research
    • Malware Analysis
    • Campaign
    • Groups & Tactics
    • Detection Science
    Vuln updates
    Reports
    Tools

Topics

Malware Analysis

avatar

Not sleeping anymore: SOMNIRECORD's wake-up call

Elastic Security Labs researchers identified a new malware family written in C++ that we refer to as SOMNIRECORD. This malware functions as a backdoor and communicates with command and control (C2) while masquerading as DNS.

By
Salim Bitam

NAPLISTENER: more bad dreams from developers of SIESTAGRAPH

Elastic Security Labs observes that the threat behind SIESTAGRAPH has shifted priorities from data theft to persistent access, deploying new malware like NAPLISTENER to evade detection.

By
Remco Sprooten

Thawing the permafrost of ICEDID Summary

Elastic Security Labs analyzed a recent ICEDID variant consisting of a loader and bot payload. By providing this research to the community end-to-end, we hope to raise awareness of the ICEDID execution chain, capabilities, and design.

By
Cyril François
Daniel Stepanic

Twice around the dance floor - Elastic discovers the PIPEDANCE backdoor

Elastic Security Labs is tracking an active intrusion into a Vietnamese organization using a recently discovered triggerable, multi-hop backdoor we are calling PIPEDANCE. This full-featured malware enables stealthy operations through the use of named

By
Daniel Stepanic

More on Malware Analysis

Videos

Exploring the REF2731 Intrusion Set

The Elastic Security Labs team has been tracking REF2731, an 5-stage intrusion set involving the PARALLAX loader and the NETWIRE RAT.

By
Salim Bitam
Daniel Stepanic
...
30 September 2022
Videos

BUGHATCH Malware Analysis

Elastic Security has performed a deep technical analysis of the BUGHATCH malware. This includes capabilities as well as defensive countermeasures.

By
Salim Bitam
09 September 2022
Videos

QBOT Malware Analysis

Elastic Security Labs releases a QBOT malware analysis report covering the execution chain. From this research, the team has produced a YARA rule, configuration-extractor, and indicators of compromises (IOCs).

By
Cyril François
24 August 2022
Videos

CUBA Ransomware Malware Analysis

Elastic Security has performed a deep technical analysis of the CUBA ransomware family. This includes malware capabilities as well as defensive countermeasures.

By
Salim Bitam
01 June 2022
Videos

BLISTER Loader

The BLISTER loader continues to be actively used to load a variety of malware.

By
Cyril François
Daniel Stepanic
...
05 May 2022
Videos

Elastic protects against data wiper malware targeting Ukraine: HERMETICWIPER

Analysis of the HERMETICWIPER malware targeting Ukranian organizations.

By
Daniel Stepanic
Mark Mager
...
01 March 2022
Videos

Going Coast to Coast - Climbing the Pyramid with the Deimos Implant

The Deimos implant was first reported in 2020 and has been in active development; employing advanced analysis countermeasures to frustrate analysis. This post details the campaign TTPs through the malware indicators.

By
Andrew Pease
Daniel Stepanic
...
12 October 2021
  • Follow us:
    TwitterLinkedInFacebook
  • Detections Repo
  • Discuss
  • Security Slack
Subscribe to our newsletter
Follow us
  • Follow us on Twitter
  • Follow us on Facebook
  • Follow us on Youtube
  • Follow us on LinkedIn

Products & Solutions

  • Enterprise Search
  • Observability
  • Security
  • Elastic Stack
  • Elasticsearch
  • Kibana
  • Integrations
  • Subscriptions
  • Pricing

Company

  • Careers
  • Board of Directors
  • Contact

Resources

  • Documentation
  • What is the ELK Stack?
  • What is Elasticsearch?
  • Migrating from Splunk
  • OpenSearch vs. Elasticsearch
  • Public Sector
Follow us

Language

English
Elastic
  • Trademarks
  • Terms of Use
  • Privacy
  • Sitemap

© . Elasticsearch B.V. All Rights Reserved

Elasticsearch is a trademark of Elasticsearch B.V., registered in the U.S. and in other countries.

Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.

© . Elasticsearch B.V. All Rights Reserved

Elastic