logo

MSP Moment: Squashing an MSSQL Attack

ID: 66c52f6b-1099-598f-a104-90fc70652022

STIX ID: report--66c52f6b-1099-598f-a104-90fc70652022

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2017-05-08

Date Updated: 2026-04-28

...
...

A client’s SQL Server was compromised after attackers brute-forced the SA account; they disabled firewall services, downloaded obfuscated backdoors over FTP, created persistence, deleted MSSQL/Windows event logs, and deployed post-exploitation tools (including a cryptocurrency miner and registry changes to block antivirus). Huntress and NTConnections detected the intrusion, reconstructed the timeline, recommended remediation, and restored the environment to contain the breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.