216.73.216.6

Demystifying PKT and Monero Cryptocurrency deployed on MSSQL servers

· Published 20/02/2025 13:44 · Modified 21/02/2025 15:29

Export JSON

Essential information

Published
20/02/2025 13:44
Modified
21/02/2025 15:29
Tags
2025-02-20 cryptocurrency mining exploitation monero mssql servers obfuscation packetcrypt pkt classic xmrig
Related entities
18 techniques (mitre), 2 malware

Description

This analysis examines a recent operation targeting , focusing on and cryptocurrencies. The attack exploits vulnerabilities to deploy mining tools, including for PKT and for . The process involves using Windows utilities and PowerShell scripts to download and execute malicious files. The miners consume significant system resources, potentially degrading performance and causing hardware wear. The attackers utilize GitHub repositories, techniques, and multi-stage attacks to evade detection. The article provides details on the attack chain, wallet information, and file analysis, highlighting the sophisticated nature of the operation. Mitigation strategies include regular software updates, strong authentication measures, and robust antivirus protection.

External references