logo

FIN13__2022__Sygnia-_Elephant_Beetle_Jan2022.pdf

ID: 0fcbc988-79d8-4f3e-8244-b250f5a7bb6e

STIX ID: report--0fcbc988-79d8-4f3e-8244-b250f5a7bb6e

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2023-10-30

Last Modified Date: 2023-10-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Sygnia details a multi-year, organized financial-theft operation named "Elephant Beetle" that targets primarily Latin American financial and commerce organizations by exploiting vulnerable Java-based web applications (WebSphere/WebLogic/SAP) to deploy web shells and malicious WARs, perform long-term reconnaissance, harvest credentials, move laterally (via SQL xp_cmdshell, WMI, SMB), and inject fraudulent transactions to siphon incremental funds; the report includes CVEs used, extensive tool and file hashes, YARA rules, MITRE ATT&CK mappings, and defensive recommendations.