Hackers are attempting to compromise cloud environments through Microsoft SQL Servers that are vulnerable to SQL injection. Microsoft security researchers report that this lateral movement technique has previously been observed in attacks on other services such as VMs and Kubernetes clusters.
See also: Mallox ransomware exploits weak MS-SQL servers to compromise networks

However, this is the first time that SQL Servers have been seen being used for this purpose. The attacks that Microsoft observed begin by exploiting a SQL injection vulnerability in an application in the target environment. This allows malicious actors to gain access to the SQL Server hosted in the Azure virtual machine with elevated privileges to execute SQL commands and extract valuable data.
This includes information about databases, table names, schemas, database versions, network configuration, and read/write/delete permissions.
If the compromised application has elevated privileges, attackers can trigger the 'xp_cmdshell' command to execute operating system (OS) commands via SQL, giving them access to the host computer.
The commands executed by attackers at this stage include the following:
- Reading directories, process lists and checking network shares.
- Download encoded and compressed PowerShell executables and scripts.
- Setting up a scheduled task to launch a backdoor.
- Recover user credentials by dropping the SAM and SECURITY registry keys.
- Data extraction using a unique method that includes the free service "webhook.site", which makes it easy to inspect and debug HTTP and email requests.
See also: Microsoft SQL servers compromised for Trigona ransomware deployment

Using a legitimate service to infiltrate data makes the activity less likely to appear suspicious or trigger any alerts from security products, allowing attackers to discreetly steal data from the host computer.
The attackers then attempted to exploit the SQL Server cloud identity to access the IMDS (Instant Metadata Service) and obtain the cloud identity access key.
In Azure, resources often assign managed identities for authentication with other cloud resources and services. If attackers have this token, they can use it to gain access to any cloud resource to which the identity has permissions.
Microsoft says that attackers failed to successfully exploit this technique due to bugs, but the approach remains valid and poses a formidable threat to organizations.
Microsoft recommends using Defender for Cloud and Defender for Endpoint to protect against SQL injection and suspicious SQLCMD activity, which are used in the observed attack.
See also: TargetCompany: Microsoft SQL servers compromised in ransomware attacks
To mitigate the threat, Microsoft recommends implementing the principle of least privilege when granting user permissions, which always puts a brake on lateral movement attempts.
Users can protect SQL servers in the Azure cloud VM by following best practices such as implementing strong security policies, keeping software up to date, using RBAC, and encrypting data. These practices enhance the security of SQL servers and reduce the risk of a security breach.
Source: bleepingcomputer
