logo

Larva-26002 Threat Actor Escalates Attacks on MS-SQL Servers

ID: 60ecdbc1-fcd7-58e5-ac65-1faccb11e551

STIX ID: report--60ecdbc1-fcd7-58e5-ac65-1faccb11e551

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-23

Author: Ddos

...
...

ASEC warns that Larva-26002 continues a multi-year campaign against poorly configured, internet-exposed MS-SQL servers, now using a new Go-based scanner named ICE Cloud that performs brute-force logins and retrieves payloads (via api.exe and ICE Cloud Launcher). The report describes delivery via BCP and common Windows tools, use of remote-control and RMM tools (AnyDesk, Teramind), reconnaissance and SQL-targeted commands, storage of malware in database tables, and links to prior ransomware distribution (Trigona, Mimic).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.