Monday, March 17, 2025
HomeCyber AttackElephant Beetle Hacking Group Attack Organizations To Steal Financial Data

Elephant Beetle Hacking Group Attack Organizations To Steal Financial Data

Published on

SIEM as a Service

Follow Us on Google News

Elephant Beetle, a financially motivated hacking group, is reportedly using more than 80 unique malicious tools and scripts to steal millions of dollars and financial data from organizations around the world.

Elephant Beetle hacking group is primarily known for its following key features:-

  • High technical skills.
  • Advance malicious tools and scripts.
  • Stealthy hiding skills.
  • Great persistence and patience.

The cybersecurity experts at Sygnia have claimed that initially, before proceeding further in any attack chain, the operators of Elephant Beetle for several months examined the victim’s financial transactions and targeted environment to exploit the vulnerabilities.

Fraudulent activity

Over a long period of time, it has been tracked and reported that several fraudulent transactions were made into the network of the compromised organizations, and even small amounts were also stolen by the threat actors of Elephant Beetle.

But, this slow and steady movement helped them in stealing millions of dollars quietly, but, here, if the victim “spotted” them, the hackers remain low for a while to hide, and then after a few times, they return again through another system.

Vulnerabilities targeted

On Linux systems, the entry point for the Elephant Beetle hacking group is the “legacy Java applications,” as it’s the most common thing that is generally targeted by the attackers.

However, the threat actors at Elephant Beetle hacking group do not prefer to buy or find zero-day vulnerabilities; instead, they prefer to exploit the known and unpatched vulnerabilities.

While in this event, the hackers have exploited the following vulnerabilities:-

  • Primefaces Application Expression Language Injection (CVE-2017-1000486)
  • WebSphere Application Server SOAP Deserialization Exploit (CVE-2015-7450)
  • SAP NetWeaver Invoker Servlet Exploit (CVE-2010-5326)
  • SAP NetWeaver ConfigServlet Remote Code Execution (EDB-ID-24963)

TTPs used

The initial goal of hackers is to deceive or bypass the detection and the security solutions since they take a long time to study the environment and transactions of their victims.

Tactics and mediums used by the attackers are:-

  • Mix malicious traffic with normal traffic.
  • Spoofing packages as legitimate ones.
  • Presenting web shells as fonts.
  • Images.
  • CSS and JS sources
  • Hiding the payload in WAR archives.

At this stage, the threat actors use the Windows API (SMB/WMI), xp_cmdshell, and other backdoors to laterally move across the network, primarily through web application servers and SQL servers.

Apart from this, the code variables and filenames used by the Elephant Beetle are in Spanish, and the C&C server IPs are Mexican. 

In the early stages of development and testing, a Java network scanner was downloaded to Virus Total from Argentina, which clearly indicates that the Elephant Beetle hacking group is associated with Latin America and may also have links with the FIN13 as well.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Kentico Xperience CMS Vulnerability Enables Remote Code Execution

In recent security research, vulnerabilities in the Kentico Xperience CMS have come to light,...

Wazuh SIEM Vulnerability Enables Remote Malicious Code Execution

A critical vulnerability, identified as CVE-2025-24016, has been discovered in the Wazuh Security Information...

Espressif Systems Flaws Allow Hackers to Execute Arbitrary Code

A series of vulnerabilities has been discovered in Espressif Systems' ESP32 devices, specifically affecting...

AI Operator Agents Helping Hackers Generate Malicious Code

Symantec's Threat Hunter Team has demonstrated how AI agents like OpenAI's Operator can now...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

AI Operator Agents Helping Hackers Generate Malicious Code

Symantec's Threat Hunter Team has demonstrated how AI agents like OpenAI's Operator can now...

BlackLock Ransomware Strikes Over 40 Organizations in Just Two Months

In a concerning escalation of cyber threats, the BlackLock ransomware group has executed a...

Android Malware Disguised as DeepSeek Steals Users’ Login Credentials

A recent cybersecurity threat has emerged in the form of Android malware masquerading as...