logo

Threat Actors Achieve Persistence After SQL Injection

ID: b6120a2a-24f3-556e-ab45-40348e6f35bb

STIX ID: report--b6120a2a-24f3-556e-ab45-40348e6f35bb

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2026-07-13

Date Updated: 2026-07-19

...
...

Huntress describes a real-world June incident where an attacker exploited an SQL injection vulnerability in an IIS-served page to gain access to an endpoint, used base64 PowerShell to download additional scripts, conducted reconnaissance (tasklist/svc exfiltration), created an administrative account and enabled Remote Desktop Services for persistence, installed BadIIS malicious IIS modules and an XMRig cryptocurrency miner (using nssm to run it as a service), and attempted defense evasion by modifying file attributes and disabling Windows Defender; the report highlights the breadth of modifications attackers may perform post-compromise and provides mitigation recommendations such as asset inventory, attack surface reduction, patching, restricted access, and root-cause investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.