HomeSecurityMalicious users take over MS-SQL Server and deploy XiebroC2

Malicious users take over MS-SQL Server and deploy XiebroC2

A sophisticated attack campaign targeting poorly managed Microsoft SQL servers has emerged, deploying the XiebroC2 command and control framework to establish persistent access to compromised systems.

See also: Web Application Security: SQL Injection, XSS, CSRF and WAF

XiebroC2

The attack exploits vulnerable credentials on publicly accessible database servers, allowing malicious users to gain initial access and escalate privileges through a multi-stage process. XiebroC2, a publicly available C2 framework similar to CobaltStrike, provides attackers with comprehensive remote control capabilities, including intelligence gathering, defense evasion, and system manipulation.

The campaign follows a predictable pattern seen in attacks on MS-SQL servers, starting with credential-based attacks and progressing to cryptocurrency mining operations. However, the inclusion of XiebroC2 represents a significant escalation in the complexity of the attack, as the framework supports cross-platform operations across Windows, Linux , and macOS.

The framework's open nature and extensive feature set make it an attractive alternative to commercial penetration testing tools, offering attackers capabilities such as reverse shells, file management, process control, and network monitoring without the associated cost.

See also: Microsoft SQL Server zero-day exposes sensitive data

Malicious users take over MS-SQL Server and deploy XiebroC2

ASEC analysts detected the malware during routine monitoring of attacks targeting MS-SQL servers, confirming the deployment of XiebroC2 alongside traditional cryptocurrency mining payloads. The framework’s implant, written in the Go programming language, demonstrates advanced techniques for avoiding detection while maintaining persistent communication with the command and control infrastructure.

The attack methodology highlights the continued vulnerability of database servers that lack proper security hardening and access controls. The attack chain demonstrates a methodical approach to privilege escalation through the deployment of JuicyPotato, a well-documented exploit tool that abuses Windows token privileges.

After successfully authenticating to the target MS-SQL server, attackers face the inherent limitation of service account privileges, which typically operate with limited access rights by design. To overcome this limitation, malicious users use JuicyPotato to exploit specific token privileges within the current process account, effectively elevating their access from service level to administrative privileges.

The privilege escalation technique exploits the impersonation privileges often granted to service accounts, allowing the exploit to abuse these privileges and create processes with elevated privileges. Once JuicyPotato successfully escalates privileges, the attackers proceed to download and execute the XiebroC2 framework using PowerShell commands.

See also: Cryptomining campaign targets PostgreSQL servers

Malicious users take over MS-SQL Server and deploy XiebroC2

This approach ensures that subsequent malicious activities operate with sufficient privileges to modify system configurations, install additional payloads, and establish persistent backdoors. The configuration data reveals the framework’s ability to collect comprehensive system information, including process IDs, hardware IDs, working directories, and user credentials before establishing encrypted communication channels with the command-and-control server located at IP address 1.94.185.235 on port 8433.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS