216.73.216.233

XiebroC2 Identified in MS-SQL Server Attack Cases

· Published 01/10/2025 07:36 · Modified 01/10/2025 09:15

Export JSON

Essential information

Published
01/10/2025 07:36
Modified
01/10/2025 09:15
Tags
2025-10-01 brute-force c2 framework coinminer dictionary attack juicypotato ms-sql privilege-escalation xiebroc2
Related entities
3 observables, 12 techniques (mitre), 3 malware

Description

A recent attack on a poorly managed server involved the use of , an open-source similar to CobaltStrike. The attackers exploited vulnerable credentials, installed for privilege escalation, and then deployed using PowerShell. supports various features including remote control, information collection, and defense evasion across multiple platforms. The malware collects system information and connects to a C&C server for command execution. To protect against such attacks, administrators are advised to use complex passwords, regularly update them, keep security software current, and implement firewalls to restrict external access to publicly accessible database servers.

External references