Threat Command

Primary threat research from Elastic Security Labs Threat Command.

Filters

Beyond Behaviors: AI-Augmented Detection Engineering with ES|QL COMPLETION

Learn how Elastic's ES|QL COMPLETION command brings LLM reasoning directly into detection rules, enabling detection engineers to build intelligent alert triage without external orchestration.

Mika Ayenson

MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites

Elastic Security Labs uncovered a ClickFix campaign using compromised legitimate sites to deliver a five-stage chain ending in MIMICRAT, a custom native C RAT with malleable C2, token theft, and SOCKS5 tunneling.

Salim Bitam

The Immutable Illusion: Pwning Your Kernel with Cloud Files

Threat actors can abuse a class of vulnerabilities to bypass security restrictions and break trust chains.

Gabriel Landau

BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign

In November 2025, Elastic Security Labs observed an intrusion affecting a multinational organization based in Southeast Asia. During the analysis of this activity, our team observed various post-compromise techniques and tooling used to deploy BADIIS malware onto a Windows web server consistent with other industry publications.

Jia Yu Chan

NANOREMOTE, cousin of FINALDRAFT

The fully-featured backdoor we call NANOREMOTE shares characteristics with malware described in REF7707 and is similar to the FINALDRAFT implant.

Daniel Stepanic

RONINGLOADER: DragonBreath’s New Path to PPL Abuse

Elastic Security Labs uncovers RONINGLOADER, a multi-stage loader deploying DragonBreath’s updated gh0st RAT variant. The campaign weaponizes signed drivers, thread-pool injection, and PPL abuse to disable Defender and evade Chinese EDR tools.

Jia Yu Chan

TOLLBOOTH: What's yours, IIS mine

REF3927 abuses publicly disclosed ASP.NET machine keys to compromise IIS servers and deploy TOLLBOOTH SEO cloaking modules globally.

Daniel Stepanic

NightMARE on 0xelm Street, a guided tour

This article describes nightMARE, a python-based library for malware researchers that was developed by Elastic Security Labs to help scale analysis. It describes how we use nightMARE to develop malware configuration extractors and carve out intelligence indicators.

Cyril François

WARMCOOKIE One Year Later: New Features and Fresh Insights

A year later: Elastic Security Labs re-examines the WARMCOOKIE backdoor.

Daniel Stepanic

FlipSwitch: a Novel Syscall Hooking Technique

FlipSwitch offers a fresh look at bypassing Linux kernel defenses, revealing a new technique in the ongoing battle between cyber attackers and defenders.

Remco Sprooten

MCP Tools: Attack Vectors and Defense Recommendations for Autonomous Agents

This research examines how Model Context Protocol (MCP) tools expand the attack surface for autonomous agents, detailing exploit vectors such as tool poisoning, orchestration injection, and rug-pull redefinitions alongside practical defense strategies.

Carolina Beretta

Investigating a Mysteriously Malformed Authenticode Signature

An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.

Elastic Security Labs