Turkish Hackers Exploiting Poorly Secured MS SQL Servers Across the Globe
ID: 3cc5ae4b-da3d-56f9-8baa-3ce2d30f5d7b
STIX ID: report--3cc5ae4b-da3d-56f9-8baa-3ce2d30f5d7b
Feed Name: The Hacker News
Securonix researchers uncovered a financially motivated campaign named RE#TURGENCE that brute-forces poorly secured MS SQL servers across the U.S., EU, and LATAM to enable xp_cmdshell-backed command execution, retrieve a PowerShell script that deploys an obfuscated Cobalt Strike beacon, and then use AnyDesk, PsExec, and Mimikatz for credential theft and lateral movement — culminating in either selling access or deploying Mimic ransomware; an OPSEC mistake exposed ties to Turkish actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
