Statistics Report on Malware Targeting Windows Database Servers in Q4 2025
ID: bff812fe-80ed-5d15-a77d-85f3864bebac
STIX ID: report--bff812fe-80ed-5d15-a77d-85f3864bebac
Feed Name: ASEC
AhnLab ASEC reports increased attacks in Q4 2025 against Internet-exposed MS-SQL/MySQL servers by the Trigona ransomware actor and associated criminal operators. The report details their workflow — credential brute-forcing, use of CLR Shell and BCP to write and deploy binaries from databases, downloaders (curl, bitsadmin, PowerShell), Rust-based scanners, installers for remote control (AnyDesk, Teramind, RDP users), and additional payloads (coinminers, proxyware, backdoors like Gh0stRAT/CobaltStrike/Meterpreter). It includes technical TTPs, sample commands, malware hashes, URLs, and IP addresses to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
