Guardicore Labs uncovered a widespread cryptojacking campaign targeting Windows MS-SQL and PHPMyAdmin servers. The malicious code dubbed Nansh0u is being carried out by a Chinese APT group. The malware has already infected nearly 50,000 servers worldwide. The attacks date back to February 26, experts observed over seven hundred new victims per day. Researchers discovered 20 versions of malicious payloads created at least once a week and immediately involved in the campaign after their creation time. The payloads used in this campaign were droppers used to deliver a cryptocurrency miner to mine TurtleCoin cryptocurrency.”]
Source: https://securityaffairs.co/wordpress/86306/hacking/nansh0u-campaign.html

