logo

Threat Actors Continuously Attacking MS-SQL Servers to Deploy ICE Cloud Scanner

ID: 8017eb2b-b209-5f67-a455-1ab75cca95f6

STIX ID: report--8017eb2b-b209-5f67-a455-1ab75cca95f6

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Larva-26002 has been actively targeting poorly managed, internet-exposed MS-SQL servers since at least January 2024—initially deploying ransomware and later evolving to a Go-based scanner (ICE Cloud Client) that harvests credentials and probes other databases. The actor abuses legitimate tools (BCP, PowerShell) to drop binaries (commonly api.exe), registers compromised hosts with a C2 to receive target lists and credentials, and forwards successful logins to build a pool of compromised servers; defenders should harden MS-SQL passwords, restrict network exposure, update endpoint protections, and monitor for unusual BCP or outbound activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.