Statistics Report on Malware Targeting Windows Database Servers in Q4 2025

Statistics Report on Malware Targeting Windows Database Servers in Q4 2025

AhnLab SEcurity intelligence Center (ASEC) utilizes the AhnLab Smart Defense (ASD) infrastructure to respond to and categorize attacks targeting MS-SQL and MySQL servers installed on Windows operating systems. This post covers the damage status of MS-SQL and MySQL servers that have become attack targets and statistics on attacks against these

GeoServer, Where Various CoinMiner Attacks Occur

GeoServer, Where Various CoinMiner Attacks Occur

AhnLab SEcurity intelligence Center (ASEC) previously covered the case of threat actors exploiting the GeoServer vulnerability to install CoinMiner and NetCat through the “CoinMiner Attacks Exploiting GeoServer Vulnerability” blog. [1] The threat actors have been continuously targeting vulnerable GeoServers to install CoinMiner. This post will cover the identified cases of

CoinMiner Malware Being Continuously Distributed via USB

CoinMiner Malware Being Continuously Distributed via USB

In February 2025, AhnLab SEcurity intelligence Center (ASEC) confirmed in their report “Cases of CoinMiner Being Spread via USB” [1] that CoinMiner malware is being spread via USB in South Korea. In July 2025, Mandiant also released a report on the same attack series and categorized the malware being installed as

ViperSoftX Attackers Target Monero

ViperSoftX Attackers Target Monero

AhnLab SEcurity intelligence Center (ASEC) has confirmed that the ViperSoftX attackers are installing coin miners to mine Monero cryptocurrency. ViperSoftX is a remote control malware that steals cryptocurrency wallet addresses. These attackers primarily distribute malware disguised as cracks or keygens for legitimate software, or as eBooks. In addition to ViperSoftX,

Analysis Report on Malicious Apps Using Advanced Detection and Evasion Techniques

Analysis Report on Malicious Apps Using Advanced Detection and Evasion Techniques

1. Overview Malware developers are using increasingly diverse techniques to evade anti-virus (AV) products. In the past, it was common for a single malicious app to implement all malicious behaviors. However, recently, apps have been discovered in which features are separated and need to be downloaded additionally, or encrypted files

Case of ActiveMQ Vulnerability Exploitation to Install Sharpire (Kinsing)

Case of ActiveMQ Vulnerability Exploitation to Install Sharpire (Kinsing)

AhnLab SEcurity intelligence Center (ASEC) has confirmed that the Kinsing threat actor is still distributing malware by exploiting known vulnerabilities. Since the disclosure of the CVE-2023-46604 vulnerability in ActiveMQ, the threat actor has been exploiting it to install malware on both Linux and Windows systems. [1] Aside from the well-known XMRig

Statistics Report on Malware Targeting Windows Database Servers in Q3 2025

Statistics Report on Malware Targeting Windows Database Servers in Q3 2025

AhnLab SEcurity intelligence Center (ASEC) utilizes the AhnLab Smart Defense (ASD) to categorize and respond to attacks targeting Windows-based MS-SQL and MySQL servers. This report will cover the current state of damage to MS-SQL and MySQL servers that became attack targets based on the logs discovered in the third quarter

CoinMiner Attacks Exploiting GeoServer Vulnerability

CoinMiner Attacks Exploiting GeoServer Vulnerability

AhnLab SEcurity intelligence Center (ASEC) has confirmed that the unpatched GeoServer is still under continuous attack. Threat actors are scanning for vulnerable GeoServer and installing CoinMiner. ASEC has also identified cases of infection in South Korea.   1. GeoServer Remote Code Execution Vulnerability (CVE-2024-36401) GeoServer is an open-source Geographic Information

Statistics Report on Malware Targeting Windows Database Servers in Q2 2025

Statistics Report on Malware Targeting Windows Database Servers in Q2 2025

Overview The AhnLab SEcurity intelligence Center (ASEC) analysis team uses the AhnLab Smart Defense (ASD) infrastructure to categorize and respond to attacks targeting Windows-based MS-SQL and MySQL servers. This report will cover the current state of damage to MS-SQL and MySQL servers that became attack targets based on the logs

Analysis of T-Rex CoinMiner Attacks Targeting Internet Cafés in Korea

Analysis of T-Rex CoinMiner Attacks Targeting Internet Cafés in Korea

AhnLab SEcurity intelligence Center (ASEC) has recently identified cases of attacks installing CoinMiners in Korean Internet cafés. The threat actor is believed to have been active since 2022, and the attacks against Internet cafés have been occurring since the second half of 2024. The method of initial access is unknown,