Elastic Security Labs Technical Lead. Lawful Neutral. Threat Hunting with the Elastic Stack author. Retired CW4.

RE work by @cyril_t_f uncovered a kill switch in the implant for an NX domain, so we registered it. It was rewarding to see the implants checking in and then terminating - hopefully giving defenders detections and time to remediate.
KREMLIN is a multi-stage credential theft toolkit targeting Brazilian banking users. New research from Elastic Security Labs (REF9334): go.es.io/4yfkg4R by @cyril_t_f and @andythevariable The infection chain combines JavaScript loaders, an optional PE injector, and a custom C++ installer. The installer downloads and installs a malicious browser extension for Chrome and Edge and/or deploys an embedded PULSAR or REMCOS RAT. This malicious extension is then used for web-browser data interception and exfiltration. KREMLIN resolves its C2 endpoints from Ethereum. Smart contracts store payload URLs and extension download locations as on-chain key-value pairs. The operators update endpoints by writing a new transaction. The extension installation bypasses Chromium's integrity system. The installer launches Chrome under a debugger, recovers the App-Bound OSCrypt key from process memory, extracts the seed from resources.pak, then regenerates the HMACs and encrypted SHA-256 hashes that Secure Preferences requires. The extension registers silently with developer mode forced on. Once active, it logs input fields, intercepts HTTP requests by configurable URL and method rules, injects attacker-controlled HTML, and exfiltrates intercepted data, cookies, and credentials over WebSocket and HTTP. Elastic Security Labs Threat Command registered the network canary domain that operates as a kill switch. We observed thousands of implants from Brazil attempting to check in to this domain. Once this domain was live, the KREMLIN loaders crash before trying to update or install the final payload, temporarily disrupting this campaign. The targeting is clear. Lure filenames impersonate PIX transfers, bank statements, and receipts from Banco do Brasil, Bradesco, Sicoob, Santander, C6 Bank, and PagBank. Ethereum transaction timestamps cluster in São Paulo working hours. Portuguese-language artifacts appear throughout the codebase.
3
3
368
This’ll calm ‘em down.
1
22
On June 17, I'm going live with @jamesspi and @danielmiessler to cover the Obsidian and Axios supply chain attacks, and how AI agents can speed response. Humans don't leave the loop; they're moved to the top of it. 10am PT / 1pm ET @elasticseclabs elastic.co/lp/agentic-ai-thr…
1
5
2,336
The attempts at environmental anti-tamper techniques to encrypt the payload were clever…just not enough. #tclbanker #ref3076
We uncovered a new Brazilian banking trojan campaign: TCLBANKER. What makes TCLBANKER notable isn’t just the malware itself, but how it spreads. The campaign uses compromised WhatsApp and Outlook accounts to propagate through trusted user relationships, deploys targeted banking overlays, and incorporates anti-analysis techniques designed to evade detection. For defenders, it’s another example of malware increasingly blending into legitimate user behavior and everyday communication channels, making detection harder and trust easier to exploit. Our latest research breaks down the infection chain, propagation methods, evasion tactics, and detection opportunities observed across the campaign. Read the full analysis: go.es.io/4ewvCKF
1
4
680
I think the really big takeaway from this is the abuse of a legitimate tool's plugin capability to execute💀scripts. Many hours of work over the weekend by @soolidsnakee @DanielStepanic and @SBousseaden.
We have identified a novel social engineering campaign abusing Obsidian, the popular note taking app, to deliver a previously undocumented RAT #PHANTOMPULSE and it’s loader #PHANTOMPULL targeting individuals in finance and crypto. The attack never exploits a vulnerability. It abuses Obsidian's own plugin ecosystem to execute code the moment a victim opens a shared vault. Full analysis: go.es.io/4cld0dB
3
12
1,544
All Python spin for the Elastic Container Project is available if anyone wants to kick the tires. Probably going to archive the Bash version at the end of 2025(ish) #elasticcontainerproject github.com/peasead/elastic-c…
2
7
1,104
@DanielStepanic and @elasticseclabs are keeping on top of #REF7707 and their new RAT - #NANOREMOTE
New from the developer of #FINALDRAFT: Meet #NANOREMOTE, a newly-discovered Windows backdoor that leverages the Google Drive API for data theft and payload staging. Get the full analysis and defense strategies: ela.st/nanoremote
2
7
931
#RONINGLOADER -> PPL abuse, the new hotness.
#ElasticSecurityLabs uncovers #RONINGLOADER, a multi-stage loader utilizing signed drivers, PPL abuse, CI Policies, and other evasion techniques to deliver #DragonBreath's gh0st RAT variant. Check it out at ela.st/roningloader
6
31
4,560
It's not too often we get to work shoulder-to-shoulder with the practitioners and researchers on the front lines. #REF3927 is an intrusion set that deploys SEO cloaking capabilities, RATs, webshells, and RMMs - largely using a novel IIS module we named #TOLLBOOTH
#ElasticSecurityLabs joins forces with @tamusystem and discloses TOLLBOOTH, an IIS module used for SEO abuse that relies on publicly exposed ASP. NET machine keys: go.es.io/3L68p57
1
5
775
Sometimes naming intrusions and families can be tough - but sometimes TAs do all the hard work. Sorry Shelby's, but @soolidsnakee and @bluish_red_ had to put you to the canvas. #shelbyc2 #shelbyloader #ref8685
We’re exposing a newly discovered #malware family that has made its home on #GitHub. SHELBY targeted a middle east telecom company, uses GH commits for C2, and shares hard-coded tokens for authentication. Read the malware and campaign breakdown: go.es.io/3DXE8Cv
6
313
The significant thing to note with the ABYSSWORKER intrusion is that this isn't just BYOD; it's BYO(Malicious)D, something that's not super common. Solid research and analysis by @cyril_t_f
Join @cyril_t_f and #ElasticSecurityLabs in exposing ABYSSWORKER, a malicious driver that silences #EDR tools and is distributed via the MEDUSA #ransomware. Get the deep details: go.es.io/4bFKnr5
4
17
1,413
A very rewarding analysis of the #REF7707 intrusion set and infra as a compendium to the #FINALDRAFT and #PATHLOADER malware disclosure from #ElasticSecurityLabs.
You’ve learned about the malware, but what about the story behind it? Explore the twists and turns of REF7707 — an adversary campaign that spans the globe: go.es.io/41eeeTY #ElasticSecurityLabs #cybersecurity #cyberattack
4
14
1,580
This is tremendously exciting. Bug bounty for rules - the commitment to openness and improvement continues. Iron sharpens iron.
We’re adding a new section to @elastic’s HackerOne Bounty Program! Today, we’re opening our SIEM and EDR rules for testing. We’re excited to have another way to thank our community for their efforts on our #detectionengineering. Get more details here: go.es.io/4hdKQCI
4
289
Cool research by @DefSecSentinel great walkthrough of these Python "coding challenges" that the DPRK is continuing to float around. elastic.co/security-labs/dpr…
3
301
Brand new research on this newly discovered family. YARA, detection logic, rules included.
#ElasticSecurityLabs is exposing Banshee Stealer — a brand new macOS infostealer with ties to browsers and cryptocurrency. This MaaS collects an immense amount of data, but you can get the details and protections here: go.es.io/3YNQeWY #malware #cryptocurrency #macos
1
3
294
Replying to @Kostastsale
Totally agree. Super valuable skill. However obligatory XKCD…
1
1
279
Tremendous work by @dez_ and @SBousseaden. New malware, new rules, new technique...what a Friday!
#ElasticSecurityLabs is exposing a new threat technique — a fresh application of MMC abuse. GRIMRESOURCE utilizes specially crafted MSC files for full code execution. Read through the breakdown from @dez_ and @SBousseaden : go.es.io/45AO0eG #threattechnique #cybersecurity
1
3
15
1,456
Legit work by @DanielStepanic taking a new backdoor apart. Includes malware analysis, observables, YARA, and an IDA string decryption plugin.
Today, #ElasticSecurityLabs is exposing WARMCOOKIE, a new backdoor that’s been utilized by threat actors posing as job recruiters. Grab a glass of milk and check out the details: go.es.io/4cfl1iN #malware #new #cybersecurity
2
9
1,078
It's humbling to share a by line with @DanielStepanic @soolidsnakee @SBousseaden for GHOSTENGINE. Tracking crypto wallets with @_xDeJesus was a fun journey.
Today, we’re unveiling an intrusion set focused on cryptomining with a new payload: GHOSTENGINE. REF4578 utilizes multiple malicious modules and BYOVD. Get the details: go.es.io/3ytg3QV #ElasticSecurityLabs #malware #cryptocurrency
4
10
1,512
🔥 work by @DanielStepanic and @SBousseaden

ALT Hot Fifthelement GIF

We’ve observed a recent uptick in LATRODECTUS, a malware loader with ties to ICEDID. This brand new article breaks down the details and highlights protections. Check it out: go.es.io/4bFp1Zo #ElasticSecurityLabs #malware
1
8
517
Replying to @ImposeCost
This is your chance to be a dear dad.
1
188

ALT Andre Braugher Hot Damn GIF

2
306
Replying to @godslittlemacro
Looking great. You look like you could be on the wall of the Overlook Hotel (Shining) or Hotel Cortez (AHS).

ALT George Clooney No GIF

1
67
Replying to @ImposeCost
Not event swag per se…Easter swag? Either way, I’m very hip.
2
50
//Fantastic// post from @SBousseaden Shits fire, yo.

ALT fire yo GIF

.@SBousseaden‘s new article explores recent Windows zero-day attacks by analyzing in-the-wild LPE examples and outlining detections that can be run in Elastic Security. Check out the three cases: CLFS, DWM, and Activation Context: go.es.io/43vV8rC #ElasticSecurityLabs
1
1
11
933
Replying to @ImposeCost
I //loved// this book. Whole new world when dealing with a concentrated IP theft effort.
2
166
Replying to @Laughing_Mantis
Devin, the AI software engineer leaks API keys in source code it writes in the first 5 seconds of its demo.
1
50
Phresh research on the #PikaBot loader. "Phresh" because I'm hip. /s
#ElasticSecurityLabs researchers @soolidsnakee and @DanielStepanic share new details about an emerging #PikaBot campaign using obfuscation to evade defenses and deploy a variety of malware payloads. Read more at elastic.co/security-labs/pik…
2
13
1,392
Threat data is cool and all, but if you can't compare it to your data, it becomes less useful. This tool takes your reams of STIX documents, converts them to ECS, and imports them into Elasticsearch (or STDOUT or a file) so you can use them for ✌️detection engineering✌️
There’s a brand new tool from #ElasticSecurityLabs! Check out the STIX to ECS converter from @andythevariable and @cyril_t_f: go.es.io/3HC1UlB #codeconverter
1
5
619
Replying to @_devonkerr_
The Kerr’s are “Back in the New York groove”. 🤘🤘
144
Replying to @corg_e
I deployed Windows XP SP2 to 8k systems on a Friday and then just went home…briefly. I also blocked VoIP across an entire state military network during the day. I survived, you’ll survive. Battle lessons every IT pro has learned.
3
644
Really impressive work by @DefSecSentinel and @ricardo21_97 on the discovery of KANDYKORN and SUGARLOADER, joined by @bluish_red_ and the team at @elasticseclabs for the REF7001 intrusion set analysis.
The DPRK was so excited about Halloween, they got a head start on passing out candy. Check out REF7001, AKA KANDYKORN – a malware distributed in cryptocurrency servers on Discord: go.es.io/46Q4Lm3 #malware #threatdiscovery #cryptocurrency #discord #ElasticSecurityLabs
1
8
14
2,440
Great work by @dez_ and @soolidsnakee
Who you gonna call? Elastic Security Labs has discovered GHOSTPULSE, a stealth loader that utilizes MSIX. Get all the details here → go.es.io/3FAX9YI #ElasticSecurityLabs #malware #threatdetection
3
21
3,174
BLOODALCHEMY wraps up the REF5961 intrusion set (so far 😏). Original research updated as well. Awesome work, as always, by @cyril_t_f
Check out BLOODALCHEMY, the new malware discovered by Elastic Security Labs. We believe this backdoor is in active development. Learn more: go.es.io/3Ffdy4Q #malware #ElasticSecurityLabs
3
11
1,725
RAT roundup!
What are EAGERBEE, RUDEBIRD, and DOWNTOWN? Check out the new SIESTAGRAPH related #malware discoveries from #ElasticSecurityLabs: go.es.io/46gqrHA
4
13
1,823
Replying to @godslittlemacro
Obligatory XKCD gem.
2
48
Replying to @br0k3ns0und
Um. I skip leg day.

ALT Spongebob Leg GIF

1
2
70
Replying to @_josehelps
Big +1 on being able to run locally.

ALT Star Wars Tarkin GIF

3
319
We were doing some research that turned out to be pretty unremarkable from a complexity standpoint but did uncover 300+ atomic indicators that we wanted to get out to the community. You can find the short summary and indicators for CONFUSED RAT here -> github.com/elastic/labs-rele…
7
19
2,343
Humbled to add our research to the great work by @JamfSoftware Threat Labs and @sekoia_io on #BlueNorOff and #RUSTBUCKET
#ElasticSecurityLabs has identified a new variant of the RUSTBUCKET malware. Check out the details and review our rules for identification here: go.es.io/3Np5Qsw
6
28
3,853
More to come on this intrusion set.
The new campaign article on JOKERSPY aims to help you understand the recently discovered intrusion around REF9134. See how #ElasticSecurityLabs identified the adversary’s movements: go.es.io/3NDh3Hh
6
382
SPECTRALVIPER hitting VN agribusiness and financial services - cool to see this linked to previous intrusions.
#ElasticSecurityLabs is tracking a threat targeting Vietnamese Agriculture and Financial industries. We’ll share their TTPs with emphasis on newly-discovered #Malware, and tell you who we think is behind it. Check out the latest here: go.es.io/3ChNch8
2
8
1,158
Replying to @nas_bench
Use sc.exe to start a service? 👇👇

ALT Straight To Jail Crime GIF

2
7
256
Diamond model!

ALT Diamond Diamonds GIF

4
236
Really fun researching some crafty hVNC malware, #LOBSHOT with @DanielStepanic @cyril_t_f @bluish_red_
#ElasticSecurityLabs highlights a new #Malware family we call LOBSHOT, deployed as part of a Google adwords malvertising campaign. Read more about this financially-motivated threat here: go.es.io/41FRzxu
4
390
Replying to @pmelson
I’m in that code block and

ALT I Dont Ron Burgundy GIF

1
69
Custom 'Naplistener' Malware a Nightmare for Network-Based Detection: bit.ly/404OmH3 by Elizabeth Montalbano
2
138
#CYBERWARCON has the best welcome banner in the industry.
6
Hey @SecurePeacock MsiDb.exe is written and executed by WINWORD.exe. msi.dll is written by WINWORD.exe and loaded by MsiDb.exe.
1
5
Check out REF2731 research - a 1, 2, 3...4...5 stage(!) intrusion set for two PARALLAX + NETWIRE campaigns. Malware & campaign analysis and an open-source payload extractor. Collab w/@DanielStepanic @soolidsnakee @bluish_red_ Enjoy, it's a journey. elastic.co/security-labs/exp…
1
9
15
#ThreatFox has been added to the @abuse_ch threat feed integration for the Elastic Agent. Bravo on contextual and enriched threat information.
11
48