Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Microsoft SQL servers hijacked to deliver Cobalt Strike and ransomware

  • September 4, 2023
Total
0
Shares
0
0
0


Unknown threat actors are targeting poorly protected Microsoft SQL servers, in an attempt to infect them with a new strain of ransomware. 

A new report from cybersecurity researchers Securonix outlines a campaign in which hackers first try to brute-force their way into MS SQL servers.

When they succeed, they do a number of things, including the deployment of a Cobalt Strike beacon, lateral movement across the target network and endpoints, and ultimately – the deployment of a ransomware strain called FreeWorld.

FreeWorld ransomware

FreeWorld seems to be a variant of a known encryptor called Mimic. While the goal of the campaign is as expected (stealing sensitive data and encrypting the endpoints) the way the hackers use the tools and infrastructure to get there is quite unique. Securonix explained in its writeup, saying: “Some of these tools include enumeration software, RAT payloads, exploitation and credential-stealing software, and finally ransomware payloads.” 

The success of the campaign depends exclusively on the strength of the password used to protect an MS SQL server, the researchers concluded. “It’s important to emphasize the importance of strong passwords, especially on publicly exposed services.” After all, it’s the servers with weak passwords that ended up being compromised.

Ransomware is one of the most popular types of cybercrime out there. After a relatively peaceful 2022, this year the number of ransomware attacks skyrocketed, figures from Coveware have shown. At the same time, awareness among potential victims is growing, resulting in fewer organizations paying the ransom demand. The percentage of compromised organizations that ended up paying the ransom demand fell to a record low of 34%, the same source claims. 

Those that did pay – ended up paying quite a lot. The average amount surpassed $700,000, up 126% compared to Q1 2023.

Via: TheHackerNews


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Starfield will let you fly between planets but it could take hours

  • September 4, 2023
View Post
Next Article
  • News

The newest 14-inch MEGABOOK T1 from Tecno is perfect for your back to school needs

  • September 4, 2023
View Post
You May Also Like
View Post
  • News

Rainbow Six Siege’s Halo crossover lets players dress as Master Chief

  • September 27, 2023
View Post
  • News

Netflix’s third most-watched movie this week is an old sci-fi film that nobody liked

  • September 27, 2023
View Post
  • News

Exela Stealer malware uses Discord to steal Windows users data

  • September 27, 2023
View Post
  • News

Finally! Toshiba launches its first 22TB hard drive — while Seagate and WD race towards 30TB

  • September 27, 2023
View Post
  • News

Final Fantasy 7: Ever Crisis is in development for PC – mobile saves can be shared

  • September 27, 2023
View Post
  • News

Almost all top GPUs are at risk of this dangerous cyberattack – here’s what you need to know

  • September 27, 2023
View Post
  • News

If you wanted an Intel Meteor Lake CPU for your next desktop PC, we’ve got some bad news

  • September 27, 2023
View Post
  • News

Apple’s rumored iPhone 15 Pro overheating fix could come with a catch

  • September 27, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.