Turkish Cyber Threat Targets MSSQL Servers With Mimic Ransomware
ID: 6e8cadd5-8797-5f10-95e8-1b08f071c75d
STIX ID: report--6e8cadd5-8797-5f10-95e8-1b08f071c75d
Feed Name: Dark Reading
Threat Score
A Securonix report details the RE#TURGENCE campaign—attributed to financially motivated Turkish actors—compromising misconfigured or vulnerable MSSQL servers across the U.S., EU, and Latin America to deploy Mimic ransomware (dropper: red25.exe), conduct lateral movement (Mimikatz, Advanced Port Scanner), and sometimes sell access; attackers exploit known MSSQL vulnerabilities, abuse xp_cmdshell for remote code execution, and use legitimate remote-management tools to blend in.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
