logo

Turkish Hackers Exploiting Poorly Secured MS SQL Servers Across the Globe

ID: 3cc5ae4b-da3d-56f9-8baa-3ce2d30f5d7b

STIX ID: report--3cc5ae4b-da3d-56f9-8baa-3ce2d30f5d7b

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-09

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Securonix researchers uncovered a financially motivated campaign named RE#TURGENCE that brute-forces poorly secured MS SQL servers across the U.S., EU, and LATAM to enable xp_cmdshell-backed command execution, retrieve a PowerShell script that deploys an obfuscated Cobalt Strike beacon, and then use AnyDesk, PsExec, and Mimikatz for credential theft and lateral movement — culminating in either selling access or deploying Mimic ransomware; an OPSEC mistake exposed ties to Turkish actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.