HomeSecurityMrbMiner malware: It has infected thousands of MSSQL databases

MrbMiner malware: Has infected thousands of MSSQL databases

Security researchers have discovered a new malware (they named it MrbMiner ) that targets MSSQL servers and installs a cryptominer .

MrbMiner malware MSSQL servers
MrbMiner malware: Has infected thousands of MSSQL servers with cryptominer

A new malware has been particularly active in recent months and has managed to compromise thousands of Microsoft SQL Servers (MSSQL) and install a cryptominer. According to researchers at Chinese company Tencent, thousands of MSSQL databases have been infected with the cryptominer.

Earlier this month, Tencent published a report detailing the malware gang. Researchers named the hackers MrbMiner, borrowing the name of the domains the criminals used to host their malware.

According to the researchers, to spread the botnet, the Internet for vulnerable MSSQL servers. Then, brute-force attacks to gain access to the administrator account.

After initial login, the hackers downloaded an assm.exe file, which they used to create a “(re)boot persistence mechanism” and add a backdoor account for future access. According to the researchers, this account has the username “Default” and the password “@ fg125kjnhn987.”

The infection process is completed by connecting to the command and control server and downloading a crypto-miner application that steals Monero (XMR), illegally using server resources and generating XMR coins in accounts controlled by the hackers.

cryptominer
MrbMiner malware: Has infected thousands of MSSQL servers with cryptominer

Researchers discovered that the malware could target both Linux and ARM

Tencent Security researchers said that so far they have only seen MSSQL databases infected. However, they discovered that the MrbMiner C&C server contained versions of the malware that were created to target Linux servers and ARM-based systems.

Analysis of the Linux version showed that there was a Monero wallet with cryptocurrencies. The address contained 3.38 XMR (~$300). This means that the MrbMiner gang has also targeted Linux systems and stolen funds, although researchers have not yet found more information about these attacks.

As we read on ZDNet, the Monero wallet used for the MbrMiner version targeting MSSQL servers had 7 XMR (~$630) stored. One might say that these amounts are very small. However, we don’t know if they represent the total amount stolen by the hackers, as crypto-mining gangs use many different addresses (wallets).

For now, system administrators should scan their MSSQL databases for the presence of a backdoor account with credentials: Default / @ fg125kjnhn987. If they find one, they should immediately perform a network-wide scan.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS