The Chinese hacker group APT-27 targets the networks of large enterprises, exploiting MySQL servers.
Most business networks use cloud platforms to store their data. Hackers, on the other hand, also use cloud services to run their bots on cloud servers.
The businesses targeted by the hackershad taken care to fix the security issues in their operating system, but the server running MySQL remained vulnerable.
Research shows that there are approximately 4.9 million MySQL servers running on public IPs. If a malicious hacker gains access to a network using MySQL, they automatically gain full access to the infected machine.
So far, 15,000 attacks have been detected. A large percentage (34%) of the attacks are focused on Germany, but attacks have also occurred in many other countries. These include the United States, France, China, Poland and Russia.
Researchers have discovered that different methods are used to abuse MYSQL servers and, by extension, compromise networks. Through these methods, hackers can install backdoors, ransomware, and more on the victim's machine.
Hackers exploit weaknesses, such as default credentials, and carry out brute-force and SQL injection attacks.
They also use WebShell and exploit vulnerabilitiesthat allow them to bypass authentication procedures and take control of the server. They can then edit, delete, or even steal data.
Attackers have the ability to distribute many malicious software (viruses, ransomware, miners) by exploiting the MySQL server.
Researchers also discovered that the APT-27 group had used the NewCore RAT to attack government entities and data centers.
After installing malicious files, hackers insert a ransom note. However, victims of the attack should not pay the ransom, because in this type of attack, hackers do not restore the affected systems, even after paying the ransom.
