logo

Trigona targeting MSSQL servers (Campaign)

ID: 5373b44a-8430-5197-b9d3-cb6395416a3c

STIX ID: report--5373b44a-8430-5197-b9d3-cb6395416a3c

Feed Name: Wiz Cloud Threat Landscape

Threat Score
72/100

Date Published: 2023-04-17

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Microsoft SQL servers are being targeted by attackers who use brute-force/dictionary attacks against weak credentials to gain access, deploy a CLR assembly-based backdoor (CLR Shell) to escalate privileges to LocalSystem, and then exploit CVE-2016-0099 to install a dropper (svcservice.exe) that launches Trigona ransomware (masquerading as svchost.exe) to encrypt files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.