Security News > 2022 > September > Microsoft SQL servers hacked in TargetCompany ransomware attacks

Microsoft SQL servers hacked in TargetCompany ransomware attacks
2022-09-24 15:12

Vulnerable Microsoft SQL servers are being targeted in a new wave of attacks with FARGO ransomware, security researchers are warning.

BleepingComputer has reported similar attacks in February, dropping Cobalt Strike beacons, and in July when threat actors hijacked vulnerable MS-SQL servers to steal bandwidth for proxy services.

Security researchers at AhnLab Security Emergency Response Center say that FARGO is one of the most prominent ransomware strains that focus on MS-SQL servers, along with GlobeImposter.

Statistical data about ransomware attacks on the ID Ransomware platform indicate that the FARGO family of file-encrypting malware is quite active.

The researchers note that the ransomware infection starts with the MS-SQL process on the compromised machine downloading a.NET file using cmd.

The FARGO ransomware strain excludes some software and directories from encryption to prevent the attacked system from becoming completely unusable.


News URL

https://www.bleepingcomputer.com/news/security/microsoft-sql-servers-hacked-in-targetcompany-ransomware-attacks/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 681 811 4530 4183 3708 13232