What We Think

Opinions

Secureworks CTU publishes research on new threat campaign targeting unsecured Elasticsearch databases

Unsecured Elasticsearch Data Replaced with Ransom Note Secureworks® Counter Threat Unit™ (CTU) researchers has identified indexes of multiple unsecured internet-facing Elasticsearch databases replaced with a ransom note. The note demands a Bitcoin payment in exchange for the data (see Figure 1). Figure 1. Ransom note dropped on exposed Elasticsearch database. (Source: Secureworks) The indexes reside...