Huntress SOC analysts investigated a series of attacks targeting endpoints running MSSQL Server as part of Fortinet Enterprise Management Server (EMS) installations. The threat actor exploited xp_cmdshell to execute commands, used finger.exe for C2 communication (IP 185.56.83.82, previously seen in other incidents), and attempted to install a ConnectWise ScreenConnect remote access instance via obfuscated PowerShell download cradles. The attack sequence appeared automated and scripted, running nearly identically across multiple customer endpoints. Notably, the attacker attempted to run msiexec against an MSI file not yet downloaded, suggesting a flawed playbook. On all monitored endpoints, the ScreenConnect installation failed. IoCs include two C2 IPs and a ScreenConnect instance ID, with MITRE ATT&CK mappings covering initial access via public-facing application exploit, PowerShell/cmd execution, msiexec and command obfuscation for defense evasion, and remote access software for C2.

5m read timeFrom huntress.com
Post cover image
Table of contents
BackgroundThe AttacksConclusionIndicatorMITRE ATT&CK Mapping
1 Impression