Blog | G5 Cyber Security

Multistage Attack Turns Elasticsearch Servers into DDoS Botnet

The attack aims to deliver BillGates/Setag Backdoor against vulnerable Elasticsearch servers. The attack targets the already patched vulnerability in the Groovy scripting engine (versions 1.3.0 1.4.2) and the vulnerability can be tracked as CVE-2015-1427. The malware was first spotted in the year 2014 and it is used to launch DDoS attacks, the toolkit includes ICMP flood, TCP flood, UDP flood, SYN flood, HTTP Flood (Layer7) and DNS query-of-reflection flood.”]

Source: https://gbhackers.com/elasticsearch-servers-ddos-botnet/

Exit mobile version