Threat Command

Primary threat research from Elastic Security Labs Threat Command.

Filters
WARMCOOKIE One Year Later: New Features and Fresh Insights

WARMCOOKIE One Year Later: New Features and Fresh Insights

A year later: Elastic Security Labs re-examines the WARMCOOKIE backdoor.

Daniel Stepanic
FlipSwitch: a Novel Syscall Hooking Technique

FlipSwitch: a Novel Syscall Hooking Technique

FlipSwitch offers a fresh look at bypassing Linux kernel defenses, revealing a new technique in the ongoing battle between cyber attackers and defenders.

Remco Sprooten
MCP Tools: Attack Vectors and Defense Recommendations for Autonomous Agents

MCP Tools: Attack Vectors and Defense Recommendations for Autonomous Agents

This research examines how Model Context Protocol (MCP) tools expand the attack surface for autonomous agents, detailing exploit vectors such as tool poisoning, orchestration injection, and rug-pull redefinitions alongside practical defense strategies.

Carolina Beretta
Investigating a Mysteriously Malformed Authenticode Signature

Investigating a Mysteriously Malformed Authenticode Signature

An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.

Elastic Security Labs
MaaS Appeal: An Infostealer Rises From The Ashes

MaaS Appeal: An Infostealer Rises From The Ashes

NOVABLIGHT is a NodeJS infostealer developed and sold as a MaaS offering; it is used primarily to steal credentials and compromise cryptowallets.

Jia Yu Chan
Taking SHELLTER: a commercial evasion framework abused in-the-wild

Taking SHELLTER: a commercial evasion framework abused in-the-wild

Elastic Security Labs detected the recent emergence of infostealers using an illicitly acquired version of the commercial evasion framework, SHELLTER, to deploy post-exploitation payloads.

Seth Goodwin
A Wretch Client: From ClickFix deception to information stealer deployment

A Wretch Client: From ClickFix deception to information stealer deployment

Elastic Security Labs detected a surge in ClickFix campaigns, using GHOSTPULSE to deploy Remote Access Trojans and data-stealing malware.

Salim Bitam
Call Stacks: No More Free Passes For Malware

Call Stacks: No More Free Passes For Malware

We explore the immense value that call stacks bring to malware detection and why Elastic considers them to be vital Windows endpoint telemetry despite the architectural limitations.

John Uhlmann
Chasing Eddies: New Rust-based InfoStealer used in CAPTCHA campaigns

Chasing Eddies: New Rust-based InfoStealer used in CAPTCHA campaigns

Elastic Security Labs walks through EDDIESTEALER, a lightweight commodity infostealer used in emerging CAPTCHA-based campaigns.

Jia Yu Chan
De-obfuscating ALCATRAZ

De-obfuscating ALCATRAZ

An exploration of techniques used by the obfuscator ALCATRAZ.

Daniel Stepanic
Misbehaving Modalities: Detecting Tools, Not Techniques

Misbehaving Modalities: Detecting Tools, Not Techniques

We explore the concept of Execution Modality and how modality-focused detections can complement behaviour-focused ones.

John Uhlmann
Bit ByBit - emulation of the DPRK's largest cryptocurrency heist

Bit ByBit - emulation of the DPRK's largest cryptocurrency heist

A high-fidelity emulation of the DPRK's largest cryptocurrency heist via a compromised macOS developer and AWS pivots.

Colson Wilhoit