---
title: "Attacking MSSQL Servers"
url: https://daily.dev/posts/attacking-mssql-servers-nrsd0osyr
source_url: https://www.huntress.com/blog/attacking-mssql-servers
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:45.792Z
updated: 2026-05-31T09:00:10.177Z
tags: ["microsoft-sql-server", "powershell"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Attacking MSSQL Servers

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 5 min read · 0 upvotes · 0 comments

## Summary

Huntress SOC analysts detail a real-world attack campaign targeting internet-exposed MSSQL servers, attributed to Turkish-speaking threat actors. The attackers used the native BCP (bulk copy) utility to extract malicious payloads — including PowerShell and batch scripts, AnyDesk, and a tunneling tool — directly from the database. Scripts were designed to create local admin accounts, enable WDigest credential caching, and establish remote access. The incident is linked to a broader pattern involving the same IP class C range across multiple incidents in late 2023 and early 2024. The post concludes with recommendations around asset inventory, attack surface reduction, and endpoint monitoring.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/attacking-mssql-servers>

## Similar posts on daily.dev

- [Threat Actors Achieve Persistence After SQL Injection](https://daily.dev/posts/threat-actors-achieve-persistence-after-sql-injection-cpfwbidol) · Huntress Blog · 5 upvotes · 0 comments

---

Tags: [#microsoft-sql-server](https://daily.dev/tags/microsoft-sql-server), [#powershell](https://daily.dev/tags/powershell)

[View this post on daily.dev](https://daily.dev/posts/attacking-mssql-servers-nrsd0osyr)
