IBM X-Force Research team discovered a new Delphi-based banking Trojan dubbed MnuBot that leverages Microsoft SQL Server for communication with the command and control (C&C) Experts found SQL server details (server address, port, username, and password) hardcoded inside the malware in an encrypted form. The malware downloads the malicious payload in as C:UsersPublicNeon.exe, this binary contains the attack logic. Mnubot uses the configuration to dynamically change the malicious activity (e.g., the banking sites that are targeted)”]
Source: https://securityaffairs.co/wordpress/73032/malware/mnubot-trojan-sql-server.html

