Information Leakage Caused by DB Client Tool

Information Leakage Caused by DB Client Tool

In recent breach incidents, threat actors have been observed not only accessing systems, but also directly querying internal databases and stealing sensitive information. Particularly, more threat actors are installing DB client tools directly on targeted systems to exfiltrate data, and legitimate tools such as DBeaver, Navicat, and sqlcmd are being

Case of Attacks Targeting MS-SQL Servers to Install Ammyy Admin

Case of Attacks Targeting MS-SQL Servers to Install Ammyy Admin

AhnLab SEcurity intelligence Center (ASEC) recently identified cases of attacks installing Ammyy Admin on poorly managed MS-SQL servers. Ammyy Admin is a remote control tool used to control systems remotely along with AnyDesk, ToDesk, TeamViewer, etc. When these tools are used properly, they enable companies and individuals to manage and

Statistical Report on Malware Targeting MS-SQL Servers in 1Q 2025

Statistical Report on Malware Targeting MS-SQL Servers in 1Q 2025

Overview The AhnLab SEcurity intelligence Center (ASEC) analysis team uses the AhnLab Smart Defense (ASD) infrastructure to categorize and respond to attacks on vulnerable MS-SQL servers. This report will cover the current state of damage to MS-SQL servers that became attack targets based on the logs discovered in 1Q 2025,

Statistical Report on Malware Targeting MS-SQL Servers in Q4 2024

Statistical Report on Malware Targeting MS-SQL Servers in Q4 2024

Overview The AhnLab SEcurity intelligence Center (ASEC) analysis team uses the AhnLab Smart Defense (ASD) infrastructure to categorize and respond to attacks on vulnerable MS-SQL servers. This report will cover the current state of damage to MS-SQL servers that became attack targets based on the logs discovered in Q4 2024,

Analysis Report on Larva-24011 Threat Actor’s Latest Attack Trend

Analysis Report on Larva-24011 Threat Actor’s Latest Attack Trend

1. Overview The Larva-24011 threat actor is targeting vulnerable systems to install CoinMiner and proxyware for financial gain. AhnLab Security Intelligence Center (ASEC) has recently observed that besides installing CoinMiner and proxyware, the threat actor is engaging in more attack cases of controlling infected systems and exfiltrating information such as

Statistical Report on Malware Targeting MS-SQL Servers in Q3 2024

Statistical Report on Malware Targeting MS-SQL Servers in Q3 2024

OverviewStatistics1. Attacks Against MS-SQL Servers2. Categorization of Malware Used in Attacks   2.1. Trojan   2.2. HackTool   2.3. Backdoor   2.4. CoinMiner   2.5. Downloader & RansomwareConclusion    Overview   The ASEC analysis team uses the AhnLab Smart Defense (ASD) infrastructure to categorize and respond to attacks on vulnerable MS-SQL servers. This report will

Case of Attack Targeting MS-SQL Servers Abusing GotoHTTP

Case of Attack Targeting MS-SQL Servers Abusing GotoHTTP

AhnLab SEcurity intelligence Center (ASEC) has been monitoring MS-SQL servers that are being managed inappropriately and recently discovered an attack case abusing GotoHTTP.   1. GotoHTTP   Remote control tools are used to control systems remotely, providing features such as remote desktop and file transfer. AnyDesk, ToDesk, RuDesktop, TeamViewer, and

Statistical Report on Malware Targeting MS-SQL Servers in Q2 2024

Statistical Report on Malware Targeting MS-SQL Servers in Q2 2024

Overview    The ASEC analysis team uses the AhnLab Smart Defense (ASD) infrastructure to categorize and respond to attacks on vulnerable MS-SQL servers. This report will cover the current state of damage to MS-SQL servers which have become the target of attacks based on the logs discovered in Q2 2024,

Analysis of Attack Case Installing SoftEther VPN on Korean ERP Server

Analysis of Attack Case Installing SoftEther VPN on Korean ERP Server

AhnLab SEcurity intelligence Center (ASEC) has recently discovered an attack case where a threat actor attacked the ERP server of a Korean corporation and installed a VPN server. In the initial compromise process, the threat actor attacked the MS-SQL service and later installed a web shell to maintain persistence and

Attacks Targeting MS-SQL Servers Detected by AhnLab EDR

Attacks Targeting MS-SQL Servers Detected by AhnLab EDR

MS-SQL servers are one of the main attack vectors used when targeting Windows systems because they use simple passwords and are open publicly to the external Internet. Threat actors find poorly managed MS-SQL servers and scan them before carrying out brute force or dictionary attacks to log in with administrator