Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

Attackers attack Windows MS-SQL and PHPMyAdmin servers around the world

Mr.Smith

Well-known member
Joined
Jun 14, 2020
Messages
82
Reaction score
13
Points
107
Awards
1
  • First post
More than 50 thousand Windows servers MS-SQL and PHPMyAdmin were infected with malware for mining cryptocurrency.

Guardicore Labs has published a detailed report on a large-scale malicious campaign for the extraction of cryptocurrency, in which the Chinese APT group implements cryptominers and rootkits into Windows MS-SQL and PHPMyAdmin servers worldwide. According to researchers, attackers have already managed to compromise more than 50 thousand servers owned by organizations in the field of health, telecommunications and IT-spheres.

The malicious campaign, called Nansh0u, was conducted from the end of February this year, but experts noticed it only in early April. The attackers found the MS-SQL and PHPMyAdmin Windows servers available on the Internet, hacked them with brute-force, and then infected them with malware. Experts have found 20 different versions of malicious modules.

After successful authorization with administrator rights, the attackers executed a series of MS-SQL commands on the compromised system and downloaded a malicious payload from the remote server that was launched with SYSTEM privileges (the known vulnerability CVE-2014-4113 in the win32k.sys driver was used). Then, the malicious module loaded the TurtleCoin cryptocurrency mining program, and to prevent the process from terminating, an expired digital certificate issued by the Verisign certification center was used. The certificate indicated the name of the bogus Chinese company Hangzhou Hootian Network Technology.

Mainly under threat are servers with unreliable credentials, in this regard, all administrators are advised to install more complex combinations of logins and passwords. The experts also provided a free script that allows you to check the system for the presence of malware.

Link to the script: github.com/guardicore/labs_campaigns/blob/master/Nansh0u/detect_nansh0u.ps1
 
Ad End 1 February 2024
Top