Hackers target Microsoft SQL servers in Mimic ransomware attacks
ID: 044892be-c9f5-5513-877e-0f0b305138df
STIX ID: report--044892be-c9f5-5513-877e-0f0b305138df
Feed Name: Bleeping Computer
Threat Score
Security researchers observed a financially motivated Turkish threat group (RE#TURGENCE) targeting internet-facing MSSQL servers via brute-force and insecure configurations to execute xp_cmdshell, deploy obfuscated Cobalt Strike implants, install AnyDesk for remote access, harvest credentials with Mimikatz, escalate to domain controllers, and ultimately deploy Mimic (N3ww4v3) ransomware (or sell access); victims were reported across the EU, US, and Latin America.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
