Reserved IP Address°C
02-23-2025
BSV
$37.81
Vol 15.87m
1.77%
BTC
$96266
Vol 16962.53m
-0.2%
BCH
$327.45
Vol 118.61m
3%
LTC
$126.5
Vol 654.97m
-2.58%
DOGE
$0.24
Vol 767.38m
0.23%
Getting your Trinity Audio player ready...

A new malicious script infecting Microsoft SQL servers has been identified, the latest cybersecurity threat to rely on digital currency computing to profit from its victims.

The campaign, which researchers say began in May 2018, has been targeting Windows machines operating SQL servers, deploying backdoors and various types of malware—including digital currency processing scripts.

Dubbed ‘Vollgar’, after the digital currency it mines, the botnet is said to use password brute-force techniques to hack servers with weak credentials. Some 2,000-3,000 machines are thought to have been infected over the last couple of weeks, with victims mainly companies and higher education facilities worldwide.

Researchers at Guardicore Labs said once a password hack has been successful, the malware goes on to affect changes to the configuration of hosted servers:

“Attackers [also] validate that certain COM classes are available – WbemScripting.SWbemLocator, Microsoft.Jet.OLEDB.4.0 and Windows Script Host Object Model (wshom). These classes support both WMI scripting and command execution through MS-SQL, which will be later used to download the initial malware binary.”

According to Guardicore, the entire infrastructure of the hack is stored on compromised computers, with its main hub traced back to a computer that had itself been infected.

“Among the files [on the C&C server] was the MS-SQL attack tool, responsible for scanning IP ranges, brute-forcing the targeted database, and executing commands remotely.”

“In addition, we found two CNC programs with GUI in Chinese, a tool for modifying files’ hash values, a portable HTTP file server (HFS), Serv-U FTP server and a copy of the executable mstsc.exe (Microsoft Terminal Services Client) used to connect to victims over RDP.”

In their report, the researchers concluded that database servers were valuable to hackers beyond digital currency processing, potentially storing huge amounts of sensitive data, such as names, usernames, passwords and credit cards.

“What makes these database servers appealing for attackers apart from their valuable CPU power is the huge amount of data they hold. These machines possibly store personal information such as usernames, passwords, credit card numbers, etc., which can fall into the attacker’s hands with only a simple brute-force.”

Recommended for you

Majorana 1 chip offers breakthroughs in quantum computing
Microsoft's Majorana 1 chip signifies a leap in quantum computing, but developers in the blockchain community should still be wary...
February 21, 2025
Ransomware losses tumble but threat remains: Chainalysis
A new report shows that collaboration between authorities and victims' refusal to negotiate with bad actors caused a decline in...
February 20, 2025
Advertisement
Advertisement
Advertisement