Cyber Security News

Hackers Targeting Vulnerable MS-SQL Servers to Deploy Backdoor Malware

A new wave of attacks on vulnerable MS-SQL Servers (Microsoft SQL) has been discovered by the cybersecurity analysts of the ASEC analysis team at AhnLab.

In these attacks, the hackers are installing the Cobalt Strike beacons on the compromised system of their victim to penetrate deeper into the victim’s network.

With open TCP port 1433, the attacks begin, and here the open TCP port 1433 implies to be MS-SQL servers. Once the attack is executed, the attacker performs a brute-force attack to crack the admin password.

Attacks Performed

In this new wave of attacks, the hackers perform two key attacks to accomplish their goal, and here they are mentioned below:-

  • Brute force attack.
  • Dictionary attack.

Miners Used

After acquiring access to the admin account and penetrating the server, the hackers deploy several crypto miners, and here they are:-

  • Lemon Duck
  • KingMiner
  • Vollgar

While later to gain a foothold in the compromised system of their victim and laterally move into the network, the attackers using the Cobalt Strike also create a backdoor.

The Cobalt Strike beacons are mainly loaded through:-

  • cmd.exe
  • powershell.exe

And once they are loaded after that, they get embedded and executed in MSBuild.exe to avoid any type of detection.

In a later stage, the beacons are embedded in the legitimate wwanmm.dll process to remain hidden inside the system file and wait for further commands from its operators.

Recommendations

Apart from this, the cybersecurity researchers have recommended a few security recommendations to mitigate such attacks, and here we have mentioned them below:-

  • Always use strong and complex passwords.
  • Don’t use any used password.
  • Always place server behind a firewall.
  • Always monitor the logs for any suspicious activity.
  • Always keep your system and software updated with the latest updates.
  • Use robust security tools.
  • Always install the available security updates on time.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago