FIN13__2022__Sygnia-_Elephant_Beetle_Jan2022.pdf
ID: 0fcbc988-79d8-4f3e-8244-b250f5a7bb6e
STIX ID: report--0fcbc988-79d8-4f3e-8244-b250f5a7bb6e
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2023-10-30
Last Modified Date: 2023-10-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Sygnia details a multi-year, organized financial-theft operation named "Elephant Beetle" that targets primarily Latin American financial and commerce organizations by exploiting vulnerable Java-based web applications (WebSphere/WebLogic/SAP) to deploy web shells and malicious WARs, perform long-term reconnaissance, harvest credentials, move laterally (via SQL xp_cmdshell, WMI, SMB), and inject fraudulent transactions to siphon incremental funds; the report includes CVEs used, extensive tool and file hashes, YARA rules, MITRE ATT&CK mappings, and defensive recommendations.
