Huntress researchers uncovered a threat actor exploiting SolarWinds Web Help Desk (CVE-2025-26399) and using a free trial Elastic Cloud SIEM instance to exfiltrate and triage victim data. The attacker used PowerShell to push system info to an attacker-controlled Elasticsearch index. The Elastic deployment, created January 28, 2026, collected data from approximately 216 unique victim hosts across government, education, finance, and other sectors. The actor used disposable emails from the Russian-registered firstmail.ltd network and routed traffic through a SAFING VPN. One of the attacker's IPs was also linked to ToolShell exploitation of Microsoft SharePoint. Kibana telemetry revealed systematic triage sessions, and the actor's own test VMs were identified within the dataset. Elastic has since taken down the malicious instance.

8m read timeFrom huntress.com
Post cover image
Table of contents
BackgroundExfil to ElasticThe deploymentThe activity