Huntress SOC analysts detail a real-world attack campaign targeting internet-exposed MSSQL servers, attributed to Turkish-speaking threat actors. The attackers used the native BCP (bulk copy) utility to extract malicious payloads — including PowerShell and batch scripts, AnyDesk, and a tunneling tool — directly from the database. Scripts were designed to create local admin accounts, enable WDigest credential caching, and establish remote access. The incident is linked to a broader pattern involving the same IP class C range across multiple incidents in late 2023 and early 2024. The post concludes with recommendations around asset inventory, attack surface reduction, and endpoint monitoring.