Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN
ID: 2b5c8d3a-2f42-523a-ac36-7364d59f6087
STIX ID: report--2b5c8d3a-2f42-523a-ac36-7364d59f6087
Feed Name: ASEC
Threat Score
**Executive summary:** This ASEC intelligence report documents an active campaign by Larva-26009 exploiting MS-SQL servers to deploy XMRig coinminer and establish persistent remote control using VShell, GotoHTTP, SoftEther VPN, backdoor accounts, and legitimate remote-access tools; it also details credential-theft activity, privilege-escalation tools, shellcode loaders, internal scanning, and provides multiple IOCs (file hashes, URLs, FQDNs, IPs) for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
