logo

Statistical Report on Malware Targeting Windows Database Servers in the Second Quarter of 2026

ID: abc9afae-ebd2-574e-90df-77464c115f88

STIX ID: report--abc9afae-ebd2-574e-90df-77464c115f88

Feed Name: ASEC

Threat Score
78/100

Date Published: 2026-07-02

Date Updated: 2026-07-20

Author: ATCP

...
...

ASEC's Q2 2026 analysis describes active attacks against MS‑SQL, MySQL and SoftEther VPN‑exposed servers that deploy CLR SqlShell and other malware (Trojans, backdoors, downloaders, coinminers). Attackers used certutil/curl/PowerShell to retrieve payloads, set the UseLogonCredential/WDigest setting for plaintext credential access, and employed BadPotato/EfsPotato for privilege escalation; the report includes an MD5 and multiple download URLs and recommends patching, stronger account management, and access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.