Plus 56 percent: More attacks on Microsoft SQL Server 

Kaspersky_news

Share post

Attacks via Microsoft SQL Server increased by 56 percent in September this year compared to last year. Malware disguised as a .PNG file was identified. These findings come from Kaspersky's latest Managed Detection and Response Report.

Microsoft SQL Server is used worldwide by large companies and SMEs for database management. Kaspersky experts have identified an increase in attacks exploiting Microsoft SQL Server processes. In September 2022, the number of attacked SQL servers was more than 3.000; this corresponds to an increase of 56 percent compared to the same period of the previous year.

Protection for MS SQL Server is neglected

"Despite the widespread use of Microsoft SQL Server, companies do not give it enough priority to protect it," said Sergey Soldierov, head of the Security Operations Center at Kaspersky. “Attacks using malicious SQL Server jobs have long been known, but are still used by cybercriminals to gain access to a company's IT infrastructure. The attackers attempted to change the server configuration to gain access to the shell and run malware through PowerShell. The compromised SQL Server then tried to run malicious PowerShell scripts that connected to external IP addresses. The PowerShell script runs malware masquerading as .PNG files from this external IP address with the 'MsiMake' attribute. This is similar to the behavior of the PurpleFox malware.”

Recommendations for organizations to protect against cyber threats

  • Always keep the software of all devices used up to date in order to prevent attackers from being able to penetrate the company network by exploiting vulnerabilities. Patches for new vulnerabilities should be installed immediately, since threat actors can no longer exploit a vulnerability that has been closed in this way.
  • Latest threat intelligence information helps cybersecurity professionals learn about attackers' current TTPs.
  • Implement a reliable endpoint security solution like Kaspersky Endpoint Security for Business, which is equipped with behavior-based detection and anomaly control to provide effective protection against known and unknown threats.
  • Kaspersky Managed Detection and Response helps detect and stop complex attacks at an early stage. In the event of an incident, the Kaspersky Incident Response service helps to respond to it and minimize the consequences.
More at Kaspersky.com

 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more