Elastic Security Labs Technical Lead. Lawful Neutral. Threat Hunting with the Elastic Stack author. Retired CW4.

Based in United States
Filter
Exclude
Time range
-
Minimum likes
Lots of rule coverage and a rad interactive timeline by @jamesspi hf-incident.threatsearch.io
When the attacker is an autonomous agent, outcome detections beat process tree trust. OpenAI's eval models escaped a research sandbox during ExploitGym testing. The agent exploited a package-registry zero-day, reached the open internet, and hit Hugging Face's dataset processing pipeline. Hugging Face reconstructed 17,000+ events from the intrusion. The TTPs were conventional: dataset pipeline RCE, credential harvest, lateral movement, self-migrating C2. The speed and alert volume were not. We mapped MITRE ATT&CK and ATLAS stages to production Elastic Defend and SIEM rules you can enable today. Full campaign analysis on the blog: go.es.io/4bg3sRK
1
6
354
So much good RE work, artifacts at multiple stages of the execution chain, and detailed analysis of the command framework - another stellar deep dive by @cyril_t_f
TELEPUZ is a new modular malware spreading via CLICKFIX-VIDAR chains. Elastic Security Labs is tracking it. Active since late April 2026. The delivery path: ClickFix social engineering tricks users into running a PowerShell command that downloads a VIDAR Go variant, which then fetches a lightweight stager and the main TELEPUZ payload. The core DLL communicates over WebSockets and pulls additional modules from C2 on demand: Keylogger Stealer Web injector: intercepts browser sessions via CDP and WebDriver BiDi, with default configs targeting financial form fields like IBANs 36 commands. Indirect syscalls. AMSI and ETW patching. NTDLL unhooking. Multiple UAC bypasses. Still in active development: the shellcode injection command returns a TODO placeholder. C2 infrastructure is small (2 domains), but fallback methods include Telegram channels, Steam profiles, DNS records, and a Polygon smart contract that doubles as a kill switch. New builds hit VirusTotal daily. The C2 footprint is small, but this thing is moving fast for something that started 2 months ago. Full technical analysis: go.es.io/4wg6i1p
1
5
533
This is how researchers should operate. Better offensive security makes better defensive security and vice versa. Iron sharpens iron.
EDRUnChoker😀registers a permanent WMI subscription with a 5-second timer runs embedded VBScript (fileless) that deletes malicious MSFT_NetQosPolicySettingData policies targeting known security products or aggressive app-path throttles. github.com/sbousseaden/EDRUn…
3
28
4,416
The attempts at environmental anti-tamper techniques to encrypt the payload were clever…just not enough. #tclbanker #ref3076
We uncovered a new Brazilian banking trojan campaign: TCLBANKER. What makes TCLBANKER notable isn’t just the malware itself, but how it spreads. The campaign uses compromised WhatsApp and Outlook accounts to propagate through trusted user relationships, deploys targeted banking overlays, and incorporates anti-analysis techniques designed to evade detection. For defenders, it’s another example of malware increasingly blending into legitimate user behavior and everyday communication channels, making detection harder and trust easier to exploit. Our latest research breaks down the infection chain, propagation methods, evasion tactics, and detection opportunities observed across the campaign. Read the full analysis: go.es.io/4ewvCKF
1
4
680
I think the really big takeaway from this is the abuse of a legitimate tool's plugin capability to execute💀scripts. Many hours of work over the weekend by @soolidsnakee @DanielStepanic and @SBousseaden.
We have identified a novel social engineering campaign abusing Obsidian, the popular note taking app, to deliver a previously undocumented RAT #PHANTOMPULSE and it’s loader #PHANTOMPULL targeting individuals in finance and crypto. The attack never exploits a vulnerability. It abuses Obsidian's own plugin ecosystem to execute code the moment a victim opens a shared vault. Full analysis: go.es.io/4cld0dB
3
12
1,544
Bravo for releasing this. There's a reason these are successful: they spend a lot of resources to make them so. Putting this stuff out in the public is how we raise all ships.
‼️ The axios lead maintainer has gone public on how he was socially engineered into installing the malware behind the npm supply chain attack. We have example images showing exactly how the attack was staged.
3
246
Speaking of finger-pointing...we're lookin' at you #UNC1069
We have discovered a massive supply chain compromise in the Axios npm package. A backdoored maintainer account delivered a cross-platform RAT for Linux, Windows & macOS, targeting the Axios package, which has ~100M weekly downloads and is in the top five most popular Node.js packages. We filed a GitHub Security Advisory to coordinate the disclosure, ensuring that the maintainers and the npm registry could act swiftly on the compromised versions. Full analysis: go.es.io/4sHybxr
2
561
All Python spin for the Elastic Container Project is available if anyone wants to kick the tires. Probably going to archive the Bash version at the end of 2025(ish) #elasticcontainerproject github.com/peasead/elastic-c…
2
7
1,104
@DanielStepanic and @elasticseclabs are keeping on top of #REF7707 and their new RAT - #NANOREMOTE
New from the developer of #FINALDRAFT: Meet #NANOREMOTE, a newly-discovered Windows backdoor that leverages the Google Drive API for data theft and payload staging. Get the full analysis and defense strategies: ela.st/nanoremote
2
7
931
#RONINGLOADER -> PPL abuse, the new hotness.
#ElasticSecurityLabs uncovers #RONINGLOADER, a multi-stage loader utilizing signed drivers, PPL abuse, CI Policies, and other evasion techniques to deliver #DragonBreath's gh0st RAT variant. Check it out at ela.st/roningloader
6
31
4,560
It's not too often we get to work shoulder-to-shoulder with the practitioners and researchers on the front lines. #REF3927 is an intrusion set that deploys SEO cloaking capabilities, RATs, webshells, and RMMs - largely using a novel IIS module we named #TOLLBOOTH
#ElasticSecurityLabs joins forces with @tamusystem and discloses TOLLBOOTH, an IIS module used for SEO abuse that relies on publicly exposed ASP. NET machine keys: go.es.io/3L68p57
1
5
775
Replying to @SBousseaden
This is how open source research is supposed to work. Responsible disclosure coupled with solid defense research. Rising tides, raises all ships. #teamwork
4
192
As defenders it’s always interesting to see how TAs view the landscape vs. the commercial checkboxes. Iron sharpens iron, good red teams make good blue teams.
3
284
Sometimes naming intrusions and families can be tough - but sometimes TAs do all the hard work. Sorry Shelby's, but @soolidsnakee and @bluish_red_ had to put you to the canvas. #shelbyc2 #shelbyloader #ref8685
We’re exposing a newly discovered #malware family that has made its home on #GitHub. SHELBY targeted a middle east telecom company, uses GH commits for C2, and shares hard-coded tokens for authentication. Read the malware and campaign breakdown: go.es.io/3DXE8Cv
6
313
The significant thing to note with the ABYSSWORKER intrusion is that this isn't just BYOD; it's BYO(Malicious)D, something that's not super common. Solid research and analysis by @cyril_t_f
Join @cyril_t_f and #ElasticSecurityLabs in exposing ABYSSWORKER, a malicious driver that silences #EDR tools and is distributed via the MEDUSA #ransomware. Get the deep details: go.es.io/4bFKnr5
4
17
1,413
A very rewarding analysis of the #REF7707 intrusion set and infra as a compendium to the #FINALDRAFT and #PATHLOADER malware disclosure from #ElasticSecurityLabs.
You’ve learned about the malware, but what about the story behind it? Explore the twists and turns of REF7707 — an adversary campaign that spans the globe: go.es.io/41eeeTY #ElasticSecurityLabs #cybersecurity #cyberattack
4
14
1,580
This is tremendously exciting. Bug bounty for rules - the commitment to openness and improvement continues. Iron sharpens iron.
We’re adding a new section to @elastic’s HackerOne Bounty Program! Today, we’re opening our SIEM and EDR rules for testing. We’re excited to have another way to thank our community for their efforts on our #detectionengineering. Get more details here: go.es.io/4hdKQCI
4
289