Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Q1 2026 Malware Statistics Report for Windows Database Servers

7ac9ea9f9d9a25c73d3267e7466cb0643f4e981bda36013ee9264feebe38b51c

TLP:CLEAR
Active

SHA-256 Hash

Description

During the first quarter of 2026, Windows-based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language strings and C&C-based scanning capabilities. This tool attempted MS-SQL authentication using predefined credentials. Attack methods primarily consisted of brute force attacks, dictionary attacks, and exploitation of unpatched systems with misconfigured accounts stemming from inadequate account management practices.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Q1 2026 Malware Statistics Report for Windows Database Servers
Pattern Type
STIX
Confidence
75%
Valid From
May 14, 2026 23:08
Total Sightings
0
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 7ac9ea9f9d9a25c73d3267e7466cb0643f4e981bda36013ee9264feebe38b51c

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.