Trigona targeting MSSQL servers (Campaign)
ID: 5373b44a-8430-5197-b9d3-cb6395416a3c
STIX ID: report--5373b44a-8430-5197-b9d3-cb6395416a3c
Feed Name: Wiz Cloud Threat Landscape
Threat Score
Date Published: 2023-04-17
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
...
...
Microsoft SQL servers are being targeted by attackers who use brute-force/dictionary attacks against weak credentials to gain access, deploy a CLR assembly-based backdoor (CLR Shell) to escalate privileges to LocalSystem, and then exploit CVE-2016-0099 to install a dropper (svcservice.exe) that launches Trigona ransomware (masquerading as svchost.exe) to encrypt files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
