Larva-26002 Threat Actor Escalates Attacks on MS-SQL Servers
ID: 60ecdbc1-fcd7-58e5-ac65-1faccb11e551
STIX ID: report--60ecdbc1-fcd7-58e5-ac65-1faccb11e551
Feed Name: securityonline.info
ASEC warns that Larva-26002 continues a multi-year campaign against poorly configured, internet-exposed MS-SQL servers, now using a new Go-based scanner named ICE Cloud that performs brute-force logins and retrieves payloads (via api.exe and ICE Cloud Launcher). The report describes delivery via BCP and common Windows tools, use of remote-control and RMM tools (AnyDesk, Teramind), reconnaissance and SQL-targeted commands, storage of malware in database tables, and links to prior ransomware distribution (Trigona, Mimic).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
