logo

Hackers target Microsoft SQL servers in Mimic ransomware attacks

ID: 044892be-c9f5-5513-877e-0f0b305138df

STIX ID: report--044892be-c9f5-5513-877e-0f0b305138df

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-01-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Security researchers observed a financially motivated Turkish threat group (RE#TURGENCE) targeting internet-facing MSSQL servers via brute-force and insecure configurations to execute xp_cmdshell, deploy obfuscated Cobalt Strike implants, install AnyDesk for remote access, harvest credentials with Mimikatz, escalate to domain controllers, and ultimately deploy Mimic (N3ww4v3) ransomware (or sell access); victims were reported across the EU, US, and Latin America.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.