Elastic Security Labs Technical Lead. Lawful Neutral. Threat Hunting with the Elastic Stack author. Retired CW4.

Joined May 2019
110 Photos and videos
Pinned Tweet
I think the really big takeaway from this is the abuse of a legitimate tool's plugin capability to execute💀scripts. Many hours of work over the weekend by @soolidsnakee @DanielStepanic and @SBousseaden.
We have identified a novel social engineering campaign abusing Obsidian, the popular note taking app, to deliver a previously undocumented RAT #PHANTOMPULSE and it’s loader #PHANTOMPULL targeting individuals in finance and crypto. The attack never exploits a vulnerability. It abuses Obsidian's own plugin ecosystem to execute code the moment a victim opens a shared vault. Full analysis: go.es.io/4cld0dB
3
12
1,466
On June 17, I'm going live with @jamesspi and @danielmiessler to cover the Obsidian and Axios supply chain attacks, and how AI agents can speed response. Humans don't leave the loop; they're moved to the top of it. 10am PT / 1pm ET @elasticseclabs elastic.co/lp/agentic-ai-thr…
1
63
This is how researchers should operate. Better offensive security makes better defensive security and vice versa. Iron sharpens iron.
EDRUnChoker😀registers a permanent WMI subscription with a 5-second timer runs embedded VBScript (fileless) that deletes malicious MSFT_NetQosPolicySettingData policies targeting known security products or aggressive app-path throttles. github.com/sbousseaden/EDRUn…
3
27
4,306
Andrew Pease retweeted
very cool research! it triggers an existing Elastic Defend behavior detection
New #redteam tool for blocking EDRs: EDRChoker Instead of fully blocking the EDR agents' connections to their server, we can throttle their bandwidth so they consistently time out when sending data, which is effectively the same as blocking but avoids triggering "block" or "drop" packet events #pentest #cybersecurity Github: TwoSevenOneT/EDRChoker
2
23
158
22,075
The attempts at environmental anti-tamper techniques to encrypt the payload were clever…just not enough. #tclbanker #ref3076
We uncovered a new Brazilian banking trojan campaign: TCLBANKER. What makes TCLBANKER notable isn’t just the malware itself, but how it spreads. The campaign uses compromised WhatsApp and Outlook accounts to propagate through trusted user relationships, deploys targeted banking overlays, and incorporates anti-analysis techniques designed to evade detection. For defenders, it’s another example of malware increasingly blending into legitimate user behavior and everyday communication channels, making detection harder and trust easier to exploit. Our latest research breaks down the infection chain, propagation methods, evasion tactics, and detection opportunities observed across the campaign. Read the full analysis: go.es.io/4ewvCKF
1
4
674
Andrew Pease retweeted
Elastic Security Labs warned that attackers are targeting crypto users through Obsidian community plugins that silently install PHANTOMPULSE malware. They lure victims into opening a shared cloud vault in the note-taking app.
6
1
6
281
Andrew Pease retweeted
points to the same Phantom panel, so convicted #PHANTOMPULSE ! h/t @soolidsnakee
1
3
210
Andrew Pease retweeted
LET'S GO! That first query caught another TX today. New domain! Presumably #PHANTOMPULSE. `https://gfsdjjg33jfk[.]com` eth.blockscout.com/tx/0xc27d…
4
3
7
1,135
Tremendous work @soolidsnakee!
"Salary Slips.exe." "Dont Delete.exe." "Important.exe." These are the filenames BRUSHWORM copies itself as when spreading across USB drives in a targeted attack on a South Asian financial institution. Elastic Security Labs uncovered two custom components working together: a modular backdoor and a persistent keylogger masquerading as libcurl.dll. Full analysis: go.es.io/4tg9vw6
1
183
Bravo for releasing this. There's a reason these are successful: they spend a lot of resources to make them so. Putting this stuff out in the public is how we raise all ships.
‼️ The axios lead maintainer has gone public on how he was socially engineered into installing the malware behind the npm supply chain attack. We have example images showing exactly how the attack was staged.
3
244
Seeing this tool in action is fantastic, but don’t sleep on the fact that it was also released for your environment github.com/elastic/supply-ch…
One of our researchers built an AI powered supply chain monitoring tool on a Friday afternoon. The following Monday night it caught the Axios npm compromise before most people knew it existed. Elastic Security Labs is open sourcing the tool. Full story by @dez_ here: go.es.io/4bOfsuq
187
Andrew Pease retweeted
Analysis of the macho malware used in the Axios supply chain compromise gist.github.com/joe-desimone…
We are working it, sharing what we know as of now - gist.github.com/joe-desimone…
5
31
123
61,125
Andrew Pease retweeted
Now let's talk attribution. @DefSecSentinel quickly pointed to DPRK 🇰🇵. Remarkable similarities to WAVESHAPER / UNC1069
Analysis of the macho malware used in the Axios supply chain compromise gist.github.com/joe-desimone…
6
34
121
46,701
Andrew Pease retweeted
Mar 31
Not to mention: @SBousseaden @RFGroenewoud @andythevariable Go follow them too, they do cool shit, constantly.
Mar 31
If you've not seen the work that @dez_, @DefSecSentinel and the whole @elasticseclabs team have published on Axios, you're missing out.
2
12
387
Andrew Pease retweeted
Mar 31
If you've not seen the work that @dez_, @DefSecSentinel and the whole @elasticseclabs team have published on Axios, you're missing out.
🧵 The axios @npmjs compromise dropped a @macOS backdoor that closely mirrors North Korea's (@DPRK) recent WAVESHAPER backdoor. Let's take a quick look the full intrusion:
2
8
1,254
Speaking of finger-pointing...we're lookin' at you #UNC1069
We have discovered a massive supply chain compromise in the Axios npm package. A backdoored maintainer account delivered a cross-platform RAT for Linux, Windows & macOS, targeting the Axios package, which has ~100M weekly downloads and is in the top five most popular Node.js packages. We filed a GitHub Security Advisory to coordinate the disclosure, ensuring that the maintainers and the npm registry could act swiftly on the compromised versions. Full analysis: go.es.io/4sHybxr
2
558
Big work by the whole crew on this. Detections first, then analysis and finger-pointing.
ElasticSecurityLabs detects the Axios npm supply chain attack across Linux, Windows & macOS. Our behavioral detections caught it without relying on static indicators. Full malware analysis dropping soon: go.es.io/488UwvJ
2
238
Andrew Pease retweeted
Replying to @IceSolst
This is *exactly* what I am feeling. But, after I chatting with folks at [un]prompted, it felt like everyone is ahead of me. The only person I chatted with that was able to concretely describe implementation details was at Elastic, and had access to OS and AI logs.
2
2
16
1,155
Andrew Pease retweeted
We are tracking #clickfix campaign hosted and served by two compromised websites. Lua in-memory script loader and a #RAT that we are naming #MimicRat. A blog post will follow soon on @elasticseclabs. www.ndibstersoft[.]com d15mawx0xveem1.cloudfront[.]net xMRi[.]neTwOrk
2
7
24
2,023