logo

TargetCompany Abusing MSSQL Servers for Ransomware (Campaign)

ID: e7f748fc-83cd-5617-91fa-19a266c660c9

STIX ID: report--e7f748fc-83cd-5617-91fa-19a266c660c9

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2024-05-02

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers investigated a series of attacks by the 'TargetCompany' group exploiting poorly managed MS-SQL servers via brute-force to gain SA access, deploy Remcos RAT and remote-control tools (including AnyDesk and a custom screen-control malware), and then install Mallox ransomware which deletes shadow copies, disables recovery, terminates processes, and propagates via shared folders. The campaigns reuse C2 infrastructure seen in prior Tor2Mine and BlueSky incidents, indicating an ongoing organized criminal campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.