logo

Threat Actors Target MS-SQL Servers to Deploy ICE Cloud Scanner Malware

ID: e5048fa8-8799-5e52-ab9c-b4b2cbb15db6

STIX ID: report--e5048fa8-8799-5e52-ab9c-b4b2cbb15db6

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Larva-26002 is actively targeting poorly secured MS-SQL servers via brute-force and dictionary attacks, deploying a Go-based scanner called ICE Cloud Client that registers with a C2, receives target lists and credentials, and reports successful compromises; attackers commonly abuse the BCP utility to export payloads (e.g., api.exe) from database tables and have reused identifiers and tooling across campaigns that previously delivered Trigona and Mimic ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.