The search engine Elasticsearch is at risk of turning into a sophisticated cryptomining botnet, which will serve to carry out denial-of-service (DDoS) attacks.
Researchers at Trend Micro have discovered a new malware that attacks public databases and servers that use old versions of the Elasticsearch software
The company said hackers are looking to find unsecured or misconfigured servers or exploit old vulnerabilities. They then install payloads, which are usually cryptomining software or even ransomware.
This malware is very sophisticated. It first identifies unpatched servers and forces them to download and execute a series of dangerous scriptsusing malicious search requests.
At first, the script tries to disable any firewall running on the target machine. Then, it “kills” any other cryptomining programsthat may be present. Finally, it downloads another script.

This second script prepares the host computer for the delivery of the final payload. The preparation involves stopping protection programs, removing filesthat configure settings, and removing all evidence of the initial infection.
Once these steps are completed, is installed the BillGates / Setag malware on the victim's machine. The malware hacks systems and allows DDoS attacks to be carried out. In addition, it can connect the machine to other infected machines to create powerful botnets.
Trend Micro researchers fear that the malware could be used for larger attacks. According to them, any malware that has the ability to evade detection and carry out multi-stage attacks is very dangerous.
Researchers believe that the criminals behind these attacks have not said their last word. It is possible that they are simply testing hacking tools and preparing for larger attacks.
Therefore, people using Elasticsearch databases and servers should immediately update their software to keep data safe.
