logo

Turkish Cyber Threat Targets MSSQL Servers With Mimic Ransomware

ID: 6e8cadd5-8797-5f10-95e8-1b08f071c75d

STIX ID: report--6e8cadd5-8797-5f10-95e8-1b08f071c75d

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-01-09

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

A Securonix report details the RE#TURGENCE campaign—attributed to financially motivated Turkish actors—compromising misconfigured or vulnerable MSSQL servers across the U.S., EU, and Latin America to deploy Mimic ransomware (dropper: red25.exe), conduct lateral movement (Mimikatz, Advanced Port Scanner), and sometimes sell access; attackers exploit known MSSQL vulnerabilities, abuse xp_cmdshell for remote code execution, and use legitimate remote-management tools to blend in.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.