Experts discovered 4,000 compromised Elasticsearch installations on Amazon AWS of open source analytics and search tool Elasticsearch that were running PoS malware. Experts found command-and-control servers for Alina and JackPoS point-of-sale malware running on the compromised installs. 99% of the infected servers are hosted on Amazon Web Services, and 52% of infected servers run Elastic Search 1.5.2 version, 47% 2.3.2 versions, and 1% for other versions.”]
Source: https://securityaffairs.co/wordpress/63019/hacking/elasticsearch-installs-pos-malware.html