Security News > 2023 > April > Microsoft SQL servers hacked to deploy Trigona ransomware

Microsoft SQL servers hacked to deploy Trigona ransomware
2023-04-19 19:26

Attackers are hacking into poorly secured and Interned-exposed Microsoft SQL servers to deploy Trigona ransomware payloads and encrypt all files.

Exe service, which they use to launch the Trigona ransomware as svchost.

First spotted in October 2022 by MalwareHunterTeam and analyzed by BleepingComputer, the Trigona ransomware operation is known for only accepting ransom payments in Monero cryptocurrency from victims worldwide.

Trigona encrypts all files on victims' devices except those in specific folders, including the Windows and Program Files directories.

The ransomware renames encrypted files by adding the.

The Trigona ransomware gang has been behind a constant stream of attacks, with at least 190 submissions to the ID Ransomware platform since the start of the year.


News URL

https://www.bleepingcomputer.com/news/security/microsoft-sql-servers-hacked-to-deploy-trigona-ransomware/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 680 810 4506 4176 3707 13199