Security News > 2022 > May > Microsoft warns of brute-force attacks targeting MSSQL servers

Microsoft warns of brute-force attacks targeting MSSQL servers
2022-05-18 13:27

Microsoft warned of brute-forcing attacks targeting Internet-exposed and poorly secured Microsoft SQL Server database servers using weak passwords.

Similar attacks against MSSQL servers were reported in March when they were targeted to deploy Gh0stCringe remote access trojans.

In a previous campaign from February, threat actors compromised MSSQL servers to drop Cobalt Strike beacons using the Microsoft SQL xp cmdshell command.

For years, MSSQL servers have been targeted as part of massive campaigns where malicious actors attempt to hijack thousands of vulnerable servers daily for various end goals.

In one such series of attacks spanning almost two years, threat actors backdoored between 2,000 and 3,000 servers with RATs after brute-forcing publicly exposed servers to deploy Monero and Vollar cryptominers.

Admins are advised not to expose them to the Internet to defend their MSSQL servers against such attacks.


News URL

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-brute-force-attacks-targeting-mssql-servers/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 365 49 1366 2821 162 4398