Threat Actors Continuously Attacking MS-SQL Servers to Deploy ICE Cloud Scanner
ID: 8017eb2b-b209-5f67-a455-1ab75cca95f6
STIX ID: report--8017eb2b-b209-5f67-a455-1ab75cca95f6
Feed Name: cybersecurityNews.com
Larva-26002 has been actively targeting poorly managed, internet-exposed MS-SQL servers since at least January 2024—initially deploying ransomware and later evolving to a Go-based scanner (ICE Cloud Client) that harvests credentials and probes other databases. The actor abuses legitimate tools (BCP, PowerShell) to drop binaries (commonly api.exe), registers compromised hosts with a C2 to receive target lists and credentials, and forwards successful logins to build a pool of compromised servers; defenders should harden MS-SQL passwords, restrict network exposure, update endpoint protections, and monitor for unusual BCP or outbound activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
