Huntress SOC analysts detail a real-world attack campaign targeting internet-exposed MSSQL servers, attributed to Turkish-speaking threat actors. The attackers used the native BCP (bulk copy) utility to extract malicious payloads — including PowerShell and batch scripts, AnyDesk, and a tunneling tool — directly from the database. Scripts were designed to create local admin accounts, enable WDigest credential caching, and establish remote access. The incident is linked to a broader pattern involving the same IP class C range across multiple incidents in late 2023 and early 2024. The post concludes with recommendations around asset inventory, attack surface reduction, and endpoint monitoring.

5m read timeFrom huntress.com
Post cover image
1 Impression