Statistics Report on Malware Targeting Windows Database Servers in Q3 2025
ID: 2421a470-d781-5296-b98f-beb821ff8aee
STIX ID: report--2421a470-d781-5296-b98f-beb821ff8aee
Feed Name: ASEC
AhnLab ASEC reports that Q3 2025 attacks targeting externally exposed MS-SQL/MySQL servers are decreasing but remain active; attackers commonly use weak credentials to deploy CLRShell, Potato privilege-escalators, coinminers, proxyware and backdoors (e.g., Gh0stRAT, CobaltStrike, Meterpreter), and a documented case involved downloading and deploying the XiebroC2 Go-based C2 after privilege escalation via JuicyPotato. The report includes specific TTPs (SA account misuse, PowerShell download, JuicyPotato escalation), sample IoCs (MD5s, URL, IP), and notes that coinmining/proxyware are frequent monetization outcomes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
