Statistical Report on Malware Targeting Windows Database Servers in Q2 2026
Contents
The AhnLab SEcurity intelligence Center (ASEC) analyzed attack logs from the second quarter of 2026 targeting MS-SQL server and MySQL server installations on Windows. This report summarizes the damage status, attack status, and the classification of the malware and tools used in the attacks.
Purpose and Scope
The targets are MS-SQL servers and MySQL servers. The attacks primarily target environments with unapplied security patches, improper configurations, and inadequate account management. The report categorizes the malware used in the attacks into Trojans, HackTools, Backdoors, CoinMiners, Downloaders, and others.
Key Statistics
In the second quarter of 2026, attack cases targeting domestic web servers running SoftEther VPN were identified. The threat actors exploited both web services and MS-SQL servers for command execution; they used certutil, curl, and PowerShell to download SoftEther VPN-related files, and ultimately installed CLR SqlShell on the MS-SQL server. Similar to a 2024 incident, evidence was also found that the attackers set the UseLogonCredential registry key to enable the WDigest plaintext password storage feature. This SqlShell supports command execution, payload download, privilege escalation using BadPotato and EfsPotato, memory dumping, user account creation, and shellcode execution.
Conclusion
After infiltrating vulnerable or poorly managed database servers, the threat actor attempted to install additional malware, perform privilege escalation, gain remote control, mine resources, and perform lateral movement. The report concludes that such attacks should be mitigated by strengthening account password management, applying the latest patches, and implementing access control for externally exposed servers.