HomeSecurityMicrosoft SQL servers compromised for Trigona ransomware deployment

Microsoft SQL servers compromised to deploy Trigona ransomware

According to new findings from security researchers, cybercriminals are invading unsecured and exposed Microsoft SQL (MS-SQL) servers to deploy Trigona ransomware payloads and encrypt files.

Trigona ransomware

MS-SQL servers are compromised through brute-force or dictionary. These are attacks that exploit easy credentials , that is, those that can be easily guessed.

After connecting to a server, the attackers deploy malware, which researchers at cybersecurity firm AhnLabhave dubbed CLR Shell.

See also: Fortra: Publicized zero-day attacks on GoAnywhere MFT

This malware is used to collect system information, change the configuration of the compromised account, and escalate privileges to LocalSystem. The malware exploits a vulnerability in the Windows Secondary Logon Service (which is necessary for Trigona ransomware to start as a service).

In the next stage of the attack (after deploying the CLR Shell malware), the attackers install a dropper malware as the svcservice.exe service. They use this to launch the Trigona ransomware as svchost.exe.

Additionally, they configure the ransomware binary to launch automatically on every system reboot via a Windows autorun key to ensure that systems will be encrypted even after reboots.

The ransomware will start disabling security systems, such as the recovery system, while also deleting any copies created through Windows Volume Shadow copies. In this way, the attackers increase the chances of receiving the ransom, since victims may not have backup copies of data elsewhere. Thus, file recovery can only be done through the hackers' decryption tool.

See also: Ransomware groups use AuKill to disable EDR software

Microsoft SQL Server
Microsoft SQL servers compromised to deploy Trigona ransomware

Trigona ransomware

Trigona ransomware was first detected in October 2022 by MalwareHunterTeam and analyzed by BleepingComputer. The hackers behind this ransomware demand a ransom to decrypt victims’ files, but they want it in Monero crypto. Attacks have been detected all over the world.

Trigona encrypts all files on victims' devices except those in specific folders, including the Windows and Program Files directories. Like most ransomware gangs today, Trigona claims to steal sensitive documents before encryption, in order to leak them if victims don't pay.

Trigona ransomware renames encrypted files by adding the extension ._locked. Finally, it leaves ransom notes named “how_to_decrypt.hta” in each folder with information about the attack. There, there is a link to the Trigona Tor trading site and a link containing the authorization key required to connect to the trading site.

The Trigona ransomware gang is behind numerous attacks, with at least 190 submissions to the ID Ransomware platform since the beginning of this year.

See also: Google fixes another active Chrome zero-day exploit

Ransomware attacks can cause significant damage to your personal and professional life. However, by taking precautions and being vigilant, you can protect yourself from this type of threat. Remember to keep your software up to date, use antivirus software , back up your important files, and be cautious when clicking on links or downloading attachments. By implementing these best practices, you will be better equipped to avoid becoming a victim of ransomware.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS