Threat Command

Primary threat research from Elastic Security Labs Threat Command.

Filters
Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective

Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective

Outlaw is a persistent Linux malware leveraging simple brute-force and mining tactics to maintain a long-lasting botnet.

Remco Sprooten
The Shelby Strategy

The Shelby Strategy

An analysis of REF8685's abuse of GitHub for C2 to evade defenses.

Salim Bitam
Shedding light on the ABYSSWORKER driver

Shedding light on the ABYSSWORKER driver

Elastic Security Labs describes ABYSSWORKER, a malicious driver used with the MEDUSA ransomware attack-chain to disable anti-malware tools.

Cyril François
AWS SNS Abuse: Data Exfiltration and Phishing

AWS SNS Abuse: Data Exfiltration and Phishing

During a recent internal collaboration, we dug into publicly known SNS abuse attempts and our knowledge of the data source to develop detection capabilities.

Terrance DeJesus
Detecting Hotkey-Based Keyloggers Using an Undocumented Kernel Data Structure

Detecting Hotkey-Based Keyloggers Using an Undocumented Kernel Data Structure

In this article, we explore what hotkey-based keyloggers are and how to detect them. Specifically, we explain how these keyloggers intercept keystrokes, then present a detection technique that leverages an undocumented hotkey table in kernel space.

Asuka Nakajima
Linux Detection Engineering - The Grand Finale on Linux Persistence

Linux Detection Engineering - The Grand Finale on Linux Persistence

By the end of this series, you'll have a robust knowledge of both common and rare Linux persistence techniques; and you'll understand how to effectively engineer detections for common and advanced adversary capabilities.

Ruben Groenewoud
Emulating AWS S3 SSE-C Ransom for Threat Detection

Emulating AWS S3 SSE-C Ransom for Threat Detection

In this article, we’ll explore how threat actors leverage Amazon S3’s Server-Side Encryption with Customer-Provided Keys (SSE-C) for ransom/extortion operations.

Terrance DeJesus
You've Got Malware: FINALDRAFT Hides in Your Drafts

You've Got Malware: FINALDRAFT Hides in Your Drafts

During a recent investigation (REF7707), Elastic Security Labs discovered new malware targeting a foreign ministry. The malware includes a custom loader and backdoor with many features including using Microsoft’s Graph API for C2 communications.

Cyril François
From South America to Southeast Asia: The Fragile Web of REF7707

From South America to Southeast Asia: The Fragile Web of REF7707

REF7707 targeted a South American foreign ministry using novel malware families. Inconsistent evasion tactics and operational security missteps exposed additional adversary-owned infrastructure.

Andrew Pease
Linux Detection Engineering - Approaching the Summit on Persistence Mechanisms

Linux Detection Engineering - Approaching the Summit on Persistence Mechanisms

Building on foundational concepts and techniques explored in the previous publications, this post discusses some creative and/or complex persistence mechanisms.

Ruben Groenewoud
Announcing the Elastic Bounty Program for Behavior Rule Protections

Announcing the Elastic Bounty Program for Behavior Rule Protections

Elastic is launching an expansion of its security bounty program, inviting researchers to test its SIEM and EDR rules for evasion and bypass techniques, starting with Windows endpoints. This initiative strengthens collaboration with the security community, ensuring Elastic’s defenses remain robust against evolving threats.

Mika Ayenson
Linux Detection Engineering - A Continuation on Persistence Mechanisms

Linux Detection Engineering - A Continuation on Persistence Mechanisms

This document continues the exploration of Linux detection engineering, emphasizing advancements in monitoring persistence mechanisms. By building on past practices and insights, it provides a roadmap for improving detection strategies in complex environments.

Ruben Groenewoud