Blog | G5 Cyber Security

Hackers Backdoor Unpatched Microsoft SQL Database Servers with Cobalt Strike

Vulnerable internet-facing Microsoft SQL Servers are being targeted by threat actors as part of a new campaign to deploy the Cobalt Strike adversary simulation tool on compromised hosts. South Korean cybersecurity company AhnLab Security Emergency Response Center (ASEC) said in a report published Monday. Attackers scan port 1433 to check for exposed MS SQL servers to perform brute force or dictionary attacks against the system administrator account, i.e., “sa” account, to attempt a log in. The next phase of the attack works by spawning a Windows command shell via the MS SQL “sqlservr.exe” process.”]

Source: https://thehackernews.com/2022/02/hackers-backdoor-unpatched-microsoft.html

Exit mobile version