• Login
Fintedex — Business, Fincance & Investment News
  • Contact
No Result
View All Result
  • Contact
No Result
View All Result
Fintedex — Business, Fincance & Investment News
No Result
View All Result
Home Technology

Microsoft SQL servers hit by Cobalt Strike attacks

Timothy Wilson by Timothy Wilson
29.09.2022
in Technology
0
0
SHARES
12
VIEWS
Share on FacebookShare on Twitter

Security researchers have identified a new campaign installing Cobalt Strike beacons on poorly protected Microsoft SQL Servers.

Plenty of MS-SQL Server instances are exposed to the internet by carrying weak passwords, something many threat actors know how to abuse – and cybersecurity researchers from Ahn Lab’s ASEC have now found someone doing just that. 

First, they scan the internet for endpoints with an open TCP port 1433. Then, they conduct brute-force attacks against those servers, trying out an infinite number of passwords until one sticks. The password needs to be relatively easy to guess, in order for the attack to work, the researchers added. 

TechRadar needs you!

We’re looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn’t take more than 60 seconds of your time, and entrants from the UK and US will have the chance to enter a draw for a £100 Amazon gift card (or equivalent in USD). Thank you for taking part.

>> Click here to start the survey in a new window

Abusing legitimate software

Once the attackers are in, it’s just a matter of preference, what they install. Sometimes it’s cryptocurrency miners such as LemonDuck, KingMiner, or Vollgar, but most of the time, it’s Cobalt Strike.

Cobalt Strike is a paid penetration testing product, often abused by threat actors for nefarious purposes. It enables persistence, and lateral movement, throughout the target network. Threat actors can use it to execute commands, log keys, escalate privileges, scan for ports, and steal credentials. What’s more, its fileless shellcode reduces the chances of the instance being spotted by antivirus solutions.

“As the beacon that receives the attacker’s command and performs the malicious behavior does not exist in a suspicious memory area and instead operates in the normal module wwanmm.dll, it can bypass memory-based detection,” the researchers explain.

Read more

> Patched Cobalt Strike vulnerabilities could have dealt a crippling blow to malicious users

> Linux systems are being bombarded with ransomware and cryptojacking attacks

> Log4Shell attacks are spreading fast after flaw exploited

While the name of the attacker(s) remains a mystery, AhnLab did say that all of the download URLs, as well as the C2 server URLs, used in these recent attacks, point to the same threat actor. 

The best way to remain secure is to keep a strong password, which includes a string of both uppercase and lowercase letters, numbers, as well as symbols. Avoid using numbers in sequence (123, 789), meaningful dates (birthdays, for example), or names that could be obtained through social engineering (street names, names of significant others, children, pets, etc.).

Strong passwords aside, users are also advised to keep the server behind a firewall, log everything, and keep both eyes out for suspicious actions. They should also make sure all of the software is frequently updated.

  • Check out our list of the best firewalls today

Via: BleepingComputer


Previous Post

New Google tool wants to make sure your apps are fully compliant before launch

Next Post

Google Search full dark mode is starting to roll out for some users

Related Posts

This James Webb telescope image may be hiding more than just the stars
Technology

This James Webb telescope image may be hiding more than just the stars

by Timothy Wilson
29.09.2022
New God of War Ragnarok abilities revealed, including incinerating blades
Technology

New God of War Ragnarok abilities revealed, including incinerating blades

by Timothy Wilson
29.09.2022
DualSense Edge: everything you need to know about the PS5 pro controller
Technology

DualSense Edge: everything you need to know about the PS5 pro controller

by Timothy Wilson
29.09.2022
Bluehost vs GoDaddy: Two top web hosting providers compared
Technology

Bluehost vs GoDaddy: Two top web hosting providers compared

by Timothy Wilson
29.09.2022
Audio-Technica’s new cheap record player with Bluetooth is a modern vinyl dream
Technology

Audio-Technica’s new cheap record player with Bluetooth is a modern vinyl dream

by Timothy Wilson
29.09.2022
Next Post

Google Search full dark mode is starting to roll out for some users

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Business
  • Opinion
  • Stock Market
  • Technology
  • Без рубрики

Fintedex delivers real-time news about the financial industry: feature stories, industry developments, opinions plus the latest on people and trends.

Categories

  • Business
  • Opinion
  • Stock Market
  • Technology
  • Без рубрики

Recent Posts

  • Tobacco Prices in France: Understanding the Implications for Your Finances
  • 7 Must-Try Employee Engagement Tips
  • NFT collection for charity: details about the UACatsDivision project

© 2021 Fintedex. Submit news release

No Result
View All Result
  • Contact

© 2021 Fintedex. Submit news release

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?