Cyber Security News

Hackers Targeting Vulnerable MS-SQL Servers to Deploy Backdoor Malware

A new wave of attacks on vulnerable MS-SQL Servers (Microsoft SQL) has been discovered by the cybersecurity analysts of the ASEC analysis team at AhnLab.

In these attacks, the hackers are installing the Cobalt Strike beacons on the compromised system of their victim to penetrate deeper into the victim’s network.

With open TCP port 1433, the attacks begin, and here the open TCP port 1433 implies to be MS-SQL servers. Once the attack is executed, the attacker performs a brute-force attack to crack the admin password.

Attacks Performed

In this new wave of attacks, the hackers perform two key attacks to accomplish their goal, and here they are mentioned below:-

  • Brute force attack.
  • Dictionary attack.

Miners Used

After acquiring access to the admin account and penetrating the server, the hackers deploy several crypto miners, and here they are:-

  • Lemon Duck
  • KingMiner
  • Vollgar

While later to gain a foothold in the compromised system of their victim and laterally move into the network, the attackers using the Cobalt Strike also create a backdoor.

The Cobalt Strike beacons are mainly loaded through:-

  • cmd.exe
  • powershell.exe

And once they are loaded after that, they get embedded and executed in MSBuild.exe to avoid any type of detection.

In a later stage, the beacons are embedded in the legitimate wwanmm.dll process to remain hidden inside the system file and wait for further commands from its operators.

Recommendations

Apart from this, the cybersecurity researchers have recommended a few security recommendations to mitigate such attacks, and here we have mentioned them below:-

  • Always use strong and complex passwords.
  • Don’t use any used password.
  • Always place server behind a firewall.
  • Always monitor the logs for any suspicious activity.
  • Always keep your system and software updated with the latest updates.
  • Use robust security tools.
  • Always install the available security updates on time.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Guru Baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Muddling Meerkat Using DNS As A Powerful Weapon For Sophistication

Hackers exploit DNS vulnerabilities to redirect users to malicious websites, launch distributed denial-of-service (DDoS) attacks…

24 mins ago

Pathfinder – New Attack Steals Sensitive Data From Modern Processors

Microarchitectural side-channel attacks misuse shared processor state to transmit information between security domains.  Although they…

41 mins ago

Beware of New Android Trojan That Executes Malicious Commands on Your Phone

Cybersecurity researchers at XLab have uncovered a new Android malware strain called "Wpeeper." This sophisticated…

2 hours ago

Authorities Seized Platform Used For Paid DDoS

On April 17, 2024, a joint effort between the Dresden Public Prosecutor’s Office and the…

2 hours ago

Ex-Infosec Designer Sentenced to Over 21 Years in Prison

Jareh Sebastian Dalke, 32, of Colorado Springs, was sentenced today to 262 months in prison…

3 hours ago

Safari is Not So Private! Safari Flaw Exposing EU iPhone Users to Trackers

A significant security flaw has been identified in Apple's Safari browser that could potentially expose…

3 hours ago