logo

Statistics Report on Malware Targeting Windows Database Servers in Q3 2025

ID: 2421a470-d781-5296-b98f-beb821ff8aee

STIX ID: report--2421a470-d781-5296-b98f-beb821ff8aee

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-10-12

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC reports that Q3 2025 attacks targeting externally exposed MS-SQL/MySQL servers are decreasing but remain active; attackers commonly use weak credentials to deploy CLRShell, Potato privilege-escalators, coinminers, proxyware and backdoors (e.g., Gh0stRAT, CobaltStrike, Meterpreter), and a documented case involved downloading and deploying the XiebroC2 Go-based C2 after privilege escalation via JuicyPotato. The report includes specific TTPs (SA account misuse, PowerShell download, JuicyPotato escalation), sample IoCs (MD5s, URL, IP), and notes that coinmining/proxyware are frequent monetization outcomes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.