CVE-2015-1427
published 2015-02-17CVE-2015-1427: The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
99.91%
100.0th percentile
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| elastic | elasticsearch | < 1.3.8 | 1.3.8 |
| elastic | elasticsearch | >= 0 < 1.7.3+dfsg-3 | 1.7.3+dfsg-3 |
| elastic | elasticsearch | >= 1.4.0 < 1.4.3 | 1.4.3 |
| redhat | fuse | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2015-1427 [CRITICAL] CWE-284 Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
Vulnerability: Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
Affected: Elastic Elasticsearch
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1427
Remediation Due Date: 2022-04-15
Red Hat
elasticsearch: remote code execution via Groovy sandbox bypass
vendor_redhat·2015-02-11·CVSS 9.8
CVE-2015-1427 [CRITICAL] elasticsearch: remote code execution via Groovy sandbox bypass
elasticsearch: remote code execution via Groovy sandbox bypass
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
It was reported that Elasticsearch versions 1.3.0-1.3.7 and 1.4.0-1.4.2 have vulnerabilities in the Groovy scripting engine. The vulnerability allows an attacker to construct Groovy scripts that escape the sandbox and execute shell commands as the user running the Elasticsearch Java VM.
Package: openshift-origin-cartridge-fuse (Red Hat OpenShift Enterprise 2) - Not affected
Package: elasticsearch (Red Hat Satellite 6) - Not affected
Package: elasticsearch (Red Hat Subscription Asset Manager) - Not affected
OSV
Improper Access Control in Elasticsearch
osv·2022-05-14
CVE-2015-1427 [HIGH] Improper Access Control in Elasticsearch
Improper Access Control in Elasticsearch
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
GHSA
Improper Access Control in Elasticsearch
ghsa·2022-05-14
CVE-2015-1427 [HIGH] CWE-284 Improper Access Control in Elasticsearch
Improper Access Control in Elasticsearch
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
OSV
CVE-2015-1427: The Groovy scripting engine in Elasticsearch before 1
osv·2015-02-17·CVSS 9.8
CVE-2015-1427 [CRITICAL] CVE-2015-1427: The Groovy scripting engine in Elasticsearch before 1
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
VulnCheck
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
vulncheck·2015·CVSS 9.8
CVE-2015-1427 [CRITICAL] CWE-284 Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
Affected: Elastic Elasticsearch
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.f5.com/labs/articles/threat-intelligence/vulnerabilities-exploits-and-malware-driving-attack-campaigns-march-2019; https://www.fortinet.com/blog/threat-research/closer-look-satan-ransomwares-propagation-technics; https://cyware.com/news/satan-ransomware-an-overview-of-the-ransomwares-variants-and-exploits-35acecd3; https://www.trendmicro.com/en_us/research/19/g/multistage-attack-delivers-billgates-setag-ba
Suricata
ET EXPLOIT Possible Elasticsearch CVE-2015-1427 Exploit Campaign SSL Certificate
suricata·2015-06-26·CVSS 9.8
CVE-2015-1427 [CRITICAL] ET EXPLOIT Possible Elasticsearch CVE-2015-1427 Exploit Campaign SSL Certificate
ET EXPLOIT Possible Elasticsearch CVE-2015-1427 Exploit Campaign SSL Certificate
Rule: alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Elasticsearch CVE-2015-1427 Exploit Campaign SSL Certificate"; flow:established,to_client; tls.cert_subject; content:"ST="; distance:0; content:"hacked"; content:"|01 09 01|"; distance:0; content:"[email protected]"; reference:url,blog.malwaremustdie.org/2015/06/mmd-0034-2015-new-elf.html; classtype:trojan-activity; sid:2021351; rev:4; metadata:attack_target Client_Endpoint, created_at 2015_06_26, cve CVE_2015_1427, deployment Perimeter, confidence Medium, signature_severity Major, tag SSL_Malicious_Cert, tag CISA_KEV, updated_at 2024_04_12;)
Suricata
ET WEB_SERVER Possible CVE-2015-1427 Elastic Search Sandbox Escape Remote Code Execution Attempt
suricata·2015-03-09·CVSS 9.8
CVE-2015-1427 [CRITICAL] ET WEB_SERVER Possible CVE-2015-1427 Elastic Search Sandbox Escape Remote Code Execution Attempt
ET WEB_SERVER Possible CVE-2015-1427 Elastic Search Sandbox Escape Remote Code Execution Attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET [9200,9292] (msg:"ET WEB_SERVER Possible CVE-2015-1427 Elastic Search Sandbox Escape Remote Code Execution Attempt"; flow:established,to_server; content:"POST /"; depth:6; content:"search"; distance:0; content:"script_fields"; distance:0; nocase; content:".class.forName"; nocase; distance:0; content:"java.lang.Runtime"; nocase; distance:0; reference:url,jordan-wright.github.io/blog/2015/03/08/elasticsearch-rce-vulnerability-cve-2015-1427; classtype:attempted-admin; sid:2020648; rev:2; metadata:created_at 2015_03_09, cve CVE_2015_1427, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_
Exploit-DB
ElasticSearch - Search Groovy Sandbox Bypass (Metasploit)
exploitdb·2015-03-16
CVE-2015-1427 ElasticSearch - Search Groovy Sandbox Bypass (Metasploit)
ElasticSearch - Search Groovy Sandbox Bypass (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 'ElasticSearch Search Groovy Sandbox Bypass',
'Description' => %q{
This module exploits a remote command execution (RCE) vulnerability in ElasticSearch,
exploitable by default on ElasticSearch prior to 1.4.3. The bug is found in the
REST API, which does not require authentication, where the search function allows
groovy code execution and its sandbox can be bypassed using java.lang.Math.class.forName
to reference arbitrary classes. It can be used to execute arbitrary Java code. This
module has been tested successfully on ElasticSearch 1.4.2 on Ubuntu Ser
Exploit-DB
ElasticSearch - Remote Code Execution
exploitdb·2015-03-11·CVSS 9.8
CVE-2015-1427 [CRITICAL] ElasticSearch - Remote Code Execution
ElasticSearch - Remote Code Execution
---
#!/bin/python2
# coding: utf-8
# Author: Darren Martyn, Xiphos Research Ltd.
# Version: 20150309.1
# Licence: WTFPL - wtfpl.net
import json
import requests
import sys
import readline
readline.parse_and_bind('tab: complete')
readline.parse_and_bind('set editing-mode vi')
__version__ = "20150309.1"
def banner():
print """\x1b[1;32m
▓█████ ██▓ ▄▄▄ ██████ ▄▄▄█████▓ ██▓ ▄████▄ ██████ ██░ ██ ▓█████ ██▓ ██▓
▓█ ▀ ▓██▒ ▒████▄ ▒██ ▒ ▓ ██▒ ▓▒▓██▒▒██▀ ▀█ ▒██ ▒ ▓██░ ██▒▓█ ▀ ▓██▒ ▓██▒
▒███ ▒██░ ▒██ ▀█▄ ░ ▓██▄ ▒ ▓██░ ▒░▒██▒▒▓█ ▄ ░ ▓██▄ ▒██▀▀██░▒███ ▒██░ ▒██░
▒▓█ ▄ ▒██░ ░██▄▄▄▄██ ▒ ██▒░ ▓██▓ ░ ░██░▒▓▓▄ ▄██▒ ▒ ██▒░▓█ ░██ ▒▓█ ▄ ▒██░ ▒██░
░▒████▒░██████▒▓█ ▓██▒▒██████▒▒ ▒██▒ ░ ░██░▒ ▓███▀ ░▒██████▒▒░▓█▒░██▓░▒████▒░██████▒░██████▒
░░ ▒░ ░░ ▒░▓ ░▒▒ ▓▒█░▒ ▒▓▒ ▒ ░ ▒ ░
Nuclei
ElasticSearch - Remote Code Execution
nuclei·CVSS 9.8
CVE-2015-1427 [CRITICAL] ElasticSearch - Remote Code Execution
ElasticSearch - Remote Code Execution
ElasticSearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script to the Groovy scripting engine.
Template:
id: CVE-2015-1427
info:
name: ElasticSearch - Remote Code Execution
author: pikpikcu
severity: high
description: ElasticSearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script to the Groovy scripting engine.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
remediation: |
Apply the latest security patches and updates provided by ElasticSearch to f
Metasploit
ElasticSearch Search Groovy Sandbox Bypass
metasploit
ElasticSearch Search Groovy Sandbox Bypass
ElasticSearch Search Groovy Sandbox Bypass
This module exploits a remote command execution (RCE) vulnerability in ElasticSearch, exploitable by default on ElasticSearch prior to 1.4.3. The bug is found in the REST API, which does not require authentication, where the search function allows groovy code execution and its sandbox can be bypassed using java.lang.Math.class.forName to reference arbitrary classes. It can be used to execute arbitrary Java code. This module has been tested successfully on ElasticSearch 1.4.2 on Ubuntu Server 12.04.
Greynoiseio
Coordinated Cloud-Based Scanning Operation Targets 75 Known Exposure Points in One Day
blogs_greynoiseio·2025-05-27
Coordinated Cloud-Based Scanning Operation Targets 75 Known Exposure Points in One Day
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Trendmicro
Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
blogs_trendmicro·2021-09-21·CVSS 9.8
CVE-2021-26084 [CRITICAL] Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Ausnutzung von Schwachstellen
## Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084, which was disclosed by Atlassian in August.
By: Nikki Madayag, Josefino Fajilago IV Sep 21, 2021 Read time: ( words)
Save to Folio
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084 , which was disclosed by Atlassian in August. Given the increasing popularity of the cryptocurrency market, we expect malware authors behind trojans like z0Miner to const
Trendmicro
Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
blogs_trendmicro·2021-09-21·CVSS 9.8
CVE-2021-26084 [CRITICAL] Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Exploits & Vulnerabilities
# Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084, which was disclosed by Atlassian in August.
By: Nikki Madayag, Josefino Fajilago IV
2021/09/21
Read time: ( words)
Save to Folio
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084, which was disclosed by Atlassian in August. Given the increasing popularity of the cryptocurrency market, we expect malware authors behind trojans like z0Miner to constantly
Trendmicro
Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
blogs_trendmicro·2021-09-21·CVSS 9.8
CVE-2021-26084 [CRITICAL] Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Exploits & Vulnerabilities
## Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084, which was disclosed by Atlassian in August.
By: Nikki Madayag, Josefino Fajilago IV 2021/09/21 Read time: ( words)
Save to Folio
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084 , which was disclosed by Atlassian in August. Given the increasing popularity of the cryptocurrency market, we expect malware authors behind trojans like z0Miner to constantly
Trendmicro
Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
blogs_trendmicro·2021-09-21·CVSS 9.8
CVE-2021-26084 [CRITICAL] Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Sfruttamento vulnerabilità
## Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084, which was disclosed by Atlassian in August.
By: Nikki Madayag, Josefino Fajilago IV Sep 21, 2021 Read time: ( words)
Save to Folio
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084 , which was disclosed by Atlassian in August. Given the increasing popularity of the cryptocurrency market, we expect malware authors behind trojans like z0Miner to constant
Trendmicro
Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
blogs_trendmicro·2021-09-21·CVSS 9.8
CVE-2021-26084 [CRITICAL] Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Exploits & Vulnerabilities
## Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084, which was disclosed by Atlassian in August.
By: Nikki Madayag, Josefino Fajilago IV Sep 21, 2021 Read time: ( words)
Save to Folio
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084 , which was disclosed by Atlassian in August. Given the increasing popularity of the cryptocurrency market, we expect malware authors behind trojans like z0Miner to constantly updat
Trendmicro
Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
blogs_trendmicro·2021-09-21·CVSS 9.8
CVE-2021-26084 [CRITICAL] Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Exploits & Vulnerabilities
## Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084, which was disclosed by Atlassian in August.
By: Nikki Madayag, Josefino Fajilago IV Sep 21, 2021 Read time: ( words)
Save to Folio
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084 , which was disclosed by Atlassian in August. Given the increasing popularity of the cryptocurrency market, we expect malware authors behind trojans like z0Miner to constant
Trendmicro
Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
blogs_trendmicro·2021-09-21·CVSS 9.8
CVE-2021-26084 [CRITICAL] Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Exploits y vulnerabilidades
## Cryptominer z0Miner Uses Newly Discovered Vulnerability CVE-2021-26084 to Its Advantage
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084, which was disclosed by Atlassian in August.
By: Nikki Madayag, Josefino Fajilago IV Sep 21, 2021 Read time: ( words)
Save to Folio
Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084 , which was disclosed by Atlassian in August. Given the increasing popularity of the cryptocurrency market, we expect malware authors behind trojans like z0Miner to constan
Unit42
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
blogs_unit42·2021-02-17
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
## Executive Summary
Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog, taken from the name of a Linux daemon called watchdogd. The WatchDog mining operation has been running since Jan. 27, 2019, and has collected at least 209 Monero (XMR), valued to be around $32,056 USD. Researchers have determined that at least 476 compromised systems, composed primarily of Windows and NIX cloud instances, have been performing mining operations at any one time for over two years.
Cryptojacking is the process of performing cryptomining operations on systems which are not owned and maintained by the mining operators. Malicious cryptojacking operations are currently estimated to affect 23% of cloud envi
Unit42
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
blogs_unit42·2021-02-17
WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## WatchDog: Exposing a Cryptojacking Campaign That’s Operated for Two Years
Nathaniel Quist
Published: February 17, 2021
Cloud Cybersecurity Research
Malware
Threat Research
Cryptojacking
GoLang
Monero
XMRig
## Executive Summary
Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog, taken from the name of a Linux daemon called watchdogd . The WatchDog mining operation has been running since Jan. 27, 2019, and has collected at least 209 Monero (XMR), valued to be around $32,056 USD. Researchers have determined that at least 476 compromised systems, composed primarily of Windows and NIX cloud instances, have
Trendmicro
Elasticsearch-Datenbanken werden zu Botnet-Zombies
blogs_trendmicro·2019-07-24·CVSS 9.8
[CRITICAL] Elasticsearch-Datenbanken werden zu Botnet-Zombies
Cyberbedrohungen
## Elasticsearch-Datenbanken werden zu Botnet-Zombies
Ein neuer Angriff auf Elasticsearch bringt Backdoors als Payload mit sich und verwandelt die betroffenen Ziele in Botnet-Zombies für Distributed Denial of Service (DDoS)-Angriffe.
By: Jindrich Karasek, Augusto Remillano II Jul 24, 2019 Read time: ( words)
Save to Folio
Originalbeitrag von Jindrich Karasek und Augusto Remillano II
Die Suchmaschine Elasticsearch ist für Cyberkriminelle dank ihres breiten Einsatzes in Unternehmen ein begehrtes Ziel . Im ersten Quartal dieses Jahres nahmen die Angriffe gegen Elasticsearch-Server zu , wobei es hauptsächlich um die Platzierung von Kryptowährungs-Mining Malware ging. Doch nun gab es einen neuen Angriff, der von dem üblichen Muster abweicht, indem er Backdoors als Payload
Trendmicro
Multistage Attack Delivers BillGates/Setag Backdoor
blogs_trendmicro·2019-07-23
Multistage Attack Delivers BillGates/Setag Backdoor
Malware
# Multistage Attack Delivers BillGates/Setag Backdoor
Elasticsearch is no stranger to cybercriminal abuse given its popularity. This year’s first quarter saw a surge of attacks — whether by exploiting vulnerabilities or taking advantage of security gaps — leveled against Elasticsearch servers.
By: Jindrich Karasek, Augusto Remillano II, Tony Bao
2019/07/23
Read time: ( words)
Save to Folio
Elasticsearch is no stranger to cybercriminal abuse given its popularity and use to organizations. In fact, this year’s first quarter saw a surge of attacks — whether by exploiting vulnerabilities or taking advantage of security gaps — leveled against Elasticsearch servers. These attacks mostly delivered cryptocurrency-mining malware, as in the case of one attack we saw last year.
The late
Trendmicro
Multistage Attack Delivers BillGates/Setag Backdoor
blogs_trendmicro·2019-07-23
Multistage Attack Delivers BillGates/Setag Backdoor
Malware
# Multistage Attack Delivers BillGates/Setag Backdoor
Elasticsearch is no stranger to cybercriminal abuse given its popularity. This year’s first quarter saw a surge of attacks — whether by exploiting vulnerabilities or taking advantage of security gaps — leveled against Elasticsearch servers.
By: Jindrich Karasek, Augusto Remillano II, Tony Bao
Jul 23, 2019
Read time: ( words)
Save to Folio
Elasticsearch is no stranger to cybercriminal abuse given its popularity and use to organizations. In fact, this year’s first quarter saw a surge of attacks — whether by exploiting vulnerabilities or taking advantage of security gaps — leveled against Elasticsearch servers. These attacks mostly delivered cryptocurrency-mining malware, as in the case of one attack we saw last year.
The la
Fortinet
A Closer Look at Satan Ransomware’s Propagation Techniques
blogs_fortinet·2019-05-20·CVSS 5.3
[MEDIUM] A Closer Look at Satan Ransomware’s Propagation Techniques
FORTIGUARD LABS THREAT RESEARCH
A Closer Look at Satan Ransomware’s Propagation Techniques
By David Maciejak and Floser Bacurio Jr. | May 20, 2019
FortiGuard Labs Breaking Threat Research
Satan ransomware first appeared in early 2017, and since then threat actors have been constantly improving the malware to infect its victims more effectively and to maximize its profits. For instance, FortiGuard Labs has discovered a campaign which was also utilizing a cryptominer malware as an additional payload to maximize its profits from its victims.
Aside from the fact that this file-encrypting malware targets both Linux and Windows platform, it also employs numerous vulnerabilities to propagate itself through public and external networks. In fact, FortiGuard Labs has discovered a new variant t
Talos
Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
blogs_talos·2019-02-26·CVSS 8.1
[HIGH] Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
## Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
Christopher Evans of Cisco Talos conducted the research for this post.
## EXECUTIVE SUMMARY
Cisco Talos warns users that they need to keep a close eye on unsecured Elasticsearch clusters. We have recently observed a spike in attacks from multiple threat actors targeting these clusters. These attackers are targeting clusters using versions 1.4.2 and lower, and are leveraging old vulnerabilities to pass scripts to search queries and drop the attacker's payloads. These scripts are being leveraged to drop both malware and cryptocurrency miners on victim machines. Talos has also been able to identify social media accounts associated with one of these threat actors. Because Elasticsearch is typically used to ma
Talos
Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
blogs_talos·2019-02-26·CVSS 8.1
[HIGH] Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch Clusters
Christopher Evans of Cisco Talos conducted the research for this post.
## EXECUTIVE SUMMARY
Cisco Talos warns users that they need to keep a close eye on unsecured Elasticsearch clusters. We have recently observed a spike in attacks from multiple threat actors targeting these clusters. These attackers are targeting clusters using versions 1.4.2 and lower, and are leveraging old vulnerabilities to pass scripts to search queries and drop the attacker's payloads. These scripts are being leveraged to drop both malware and cryptocurrency miners on victim machines. Talos has also been able to identify social media accounts associated with one of these threat actors. Because Elasticsearch is typically used to manage very large datasets, the repercussions of a successful attack on a cluster coul
Tenable
Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
blogs_tenable·2018-12-13·CVSS 8.1
CVE-2014-3120 [HIGH] Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
Blog / Cyber Exposure Alerts
Subscribe
# Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
Satnam Narang
December 13, 2018
2 Min Read
Attackers are actively scanning for vulnerable Elasticsearch systems in order to implant cryptocurrency mining scripts.
### Background
In recent weeks, attackers have been observed scanning for vulnerabilities in Elasticsearch, a distributed, RESTful search and analytics engine. According to research from Trend Micro, the attackers are targeting unpatched Elasticsearch systems using vulnerabilities from 2014 and 2015 to break into systems in order to implant cryptocurrency mining (also known as “coinminer”) scripts. These scripts are designed to hijack a system’s computing resources in a race to s
Tenable
Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
blogs_tenable·2018-12-13·CVSS 8.1
[HIGH] Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
Recorded Future
This Bot Is Out for Brains: ElasticZombie Exploiting Elasticsearch Vulnerabilities
blogs_recorded_future·CVSS 9.8
[CRITICAL] This Bot Is Out for Brains: ElasticZombie Exploiting Elasticsearch Vulnerabilities
## This Bot Is Out for Brains: ElasticZombie Exploiting Elasticsearch Vulnerabilities
While recently mining our Recorded Future alerts (event, entity, and keyword matches on the Web) for new attacker TTPs (techniques, tactics, and procedures) we came across an interesting and trending text fragment — ElasticZombie Botnet.
The references led us to the Romanian Security Team forums where Nytro recently posted an illuminating narrative by Markus Manzke about a “scan and exploit” campaign — ElasticZombie Botnet — that identifies vulnerable Elasticsearch instances, exploits affected Linux servers, and subsequently installs a bot that maintains persistence on the system, communicates with a command and control (C2) server, and ultimately participates in denial-of-service (DoS) attacks.
Mr. Ma
Greynoiseio
NoiseLetter April 2025
blogs_greynoiseio
NoiseLetter April 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
Malicious Tag Roundup (May 24-Jun 4, 2021)
blogs_greynoiseio·CVSS 9.8
[CRITICAL] Malicious Tag Roundup (May 24-Jun 4, 2021)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Recorded Future
This Bot Is Out for Brains: ElasticZombie Exploiting Elasticsearch Vulnerabilities
blogs_recorded_future·CVSS 9.8
[CRITICAL] This Bot Is Out for Brains: ElasticZombie Exploiting Elasticsearch Vulnerabilities
# This Bot Is Out for Brains: ElasticZombie Exploiting Elasticsearch Vulnerabilities
While recently mining our Recorded Future alerts (event, entity, and keyword matches on the Web) for new attacker TTPs (techniques, tactics, and procedures) we came across an interesting and trending text fragment — ElasticZombie Botnet.
The references led us to the Romanian Security Team forums where Nytro recently posted an illuminating narrative by Markus Manzke about a “scan and exploit” campaign — ElasticZombie Botnet — that identifies vulnerable Elasticsearch instances, exploits affected Linux servers, and subsequently installs a bot that maintains persistence on the system, communicates with a command and control (C2) server, and ultimately participates in denial-of-service (DoS) attacks.
Mr. Man
Bugzilla
CVE-2015-1427 elasticsearch: remote code execution via Groovy sandbox bypass
bugzilla·2015-02-12·CVSS 8.1
CVE-2015-1427 [HIGH] CVE-2015-1427 elasticsearch: remote code execution via Groovy sandbox bypass
CVE-2015-1427 elasticsearch: remote code execution via Groovy sandbox bypass
It was reported that Elasticsearch versions 1.3.0-1.3.7 and 1.4.0-1.4.2 have vulnerabilities in the Groovy scripting engine. The vulnerability allows an attacker to construct Groovy scripts that escape the sandbox and execute shell commands as the user running the Elasticsearch Java VM.
Upstream bug report:
https://github.com/elasticsearch/elasticsearch/issues/9655
Upstream fixes:
1.3: https://github.com/elasticsearch/elasticsearch/commit/69735b0f4ab9ad7df4b82e8c917589b52cb9978c
1.4: https://github.com/elasticsearch/elasticsearch/commit/4e952b2d75de6ca4caf4b6743462714f3b60d07f
1.x: https://github.com/elasticsearch/elasticsearch/commit/716f0b24dc5414616e8dc0590dbfcfa0081be892
Mitigation:
Users can address the v
http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.htmlhttp://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remote-Code-Execution.htmlhttp://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/http://www.securityfocus.com/archive/1/534689/100/0/threadedhttp://www.securityfocus.com/bid/72585https://access.redhat.com/errata/RHSA-2017:0868https://exchange.xforce.ibmcloud.com/vulnerabilities/100850https://www.elastic.co/community/security/http://packetstormsecurity.com/files/130368/Elasticsearch-1.3.7-1.4.2-Sandbox-Escape-Command-Execution.htmlhttp://packetstormsecurity.com/files/130784/ElasticSearch-Unauthenticated-Remote-Code-Execution.htmlhttp://www.elasticsearch.com/blog/elasticsearch-1-4-3-1-3-8-released/http://www.securityfocus.com/archive/1/534689/100/0/threadedhttp://www.securityfocus.com/bid/72585https://access.redhat.com/errata/RHSA-2017:0868https://exchange.xforce.ibmcloud.com/vulnerabilities/100850https://www.elastic.co/community/security/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1427
2015-02-17
Published
2022-03-25
Added to CISA KEV
Exploited in the wild