A sophisticated attack campaign targeting poorly managed Microsoft SQL servers has emerged, deploying the XiebroC2 command and control framework to establish persistent access to compromised systems.
See also: Web Application Security: SQL Injection, XSS, CSRF and WAF

The attack exploits vulnerable credentials on publicly accessible database servers, allowing malicious users to gain initial access and escalate privileges through a multi-stage process. XiebroC2, a publicly available C2 framework similar to CobaltStrike, provides attackers with comprehensive remote control capabilities, including intelligence gathering, defense evasion, and system manipulation.
The campaign follows a predictable pattern seen in attacks on MS-SQL servers, starting with credential-based attacks and progressing to cryptocurrency mining operations. However, the inclusion of XiebroC2 represents a significant escalation in the complexity of the attack, as the framework supports cross-platform operations across Windows, Linux , and macOS.
The framework's open nature and extensive feature set make it an attractive alternative to commercial penetration testing tools, offering attackers capabilities such as reverse shells, file management, process control, and network monitoring without the associated cost.
See also: Microsoft SQL Server zero-day exposes sensitive data

ASEC analysts detected the malware during routine monitoring of attacks targeting MS-SQL servers, confirming the deployment of XiebroC2 alongside traditional cryptocurrency mining payloads. The framework’s implant, written in the Go programming language, demonstrates advanced techniques for avoiding detection while maintaining persistent communication with the command and control infrastructure.
The attack methodology highlights the continued vulnerability of database servers that lack proper security hardening and access controls. The attack chain demonstrates a methodical approach to privilege escalation through the deployment of JuicyPotato, a well-documented exploit tool that abuses Windows token privileges.
After successfully authenticating to the target MS-SQL server, attackers face the inherent limitation of service account privileges, which typically operate with limited access rights by design. To overcome this limitation, malicious users use JuicyPotato to exploit specific token privileges within the current process account, effectively elevating their access from service level to administrative privileges.
The privilege escalation technique exploits the impersonation privileges often granted to service accounts, allowing the exploit to abuse these privileges and create processes with elevated privileges. Once JuicyPotato successfully escalates privileges, the attackers proceed to download and execute the XiebroC2 framework using PowerShell commands.
See also: Cryptomining campaign targets PostgreSQL servers

This approach ensures that subsequent malicious activities operate with sufficient privileges to modify system configurations, install additional payloads, and establish persistent backdoors. The configuration data reveals the framework’s ability to collect comprehensive system information, including process IDs, hardware IDs, working directories, and user credentials before establishing encrypted communication channels with the command-and-control server located at IP address 1.94.185.235 on port 8433.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
