During the first quarter of 2026, Windows-based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language strings and C&C-based scanning capabilities. This tool attempted MS-SQL authentication using predefined credentials. Attack methods primarily consisted of brute force attacks, dictionary attacks, and exploitation of unpatched systems with misconfigured accounts stemming from inadequate account management practices.
Executive Summary
Larva-26002 is a threat actor targeting Windows-based MS-SQL and MySQL database servers through malicious attacks involving credential brute force, dictionary attacks, and exploitation of unpatched systems. The actor deploys a Go-based scanner named ICE Cloud to access these systems using predefined credentials and Turkish language strings in their toolset.
Goals & Targeting
Larva-26002 appears to target sectors that maintain sensitive databases, such as financial institutions, healthcare providers, and critical infrastructure organizations. Their focus on MS-SQL and MySQL suggests an interest in data extraction and potential disruption of operational systems. The actor's geographic targeting is currently undefined due to limited intelligence but may be focused on regions with weaker cybersecurity practices or underpatched systems. The use of predefined credentials indicates a desire to exploit poor account management practices rather than advanced technical vulnerabilities. Their goal likely involves data theft, espionage, or sabotage.
Enhanced Description
Larva-26002 primarily focuses on compromising database servers, leveraging a combination of brute force, dictionary attacks, and exploitation techniques targeting misconfigured and unpatched systems. The actor employs tools such as BCP, curl, bitsadmin, and PowerShell to deploy their Go-based ICE Cloud scanner. This tool identifies MS-SQL authentication vulnerabilities using predefined credentials and attempts unauthorized access. Larva-26002's activities are characterized by their systematic approach to scanning and exploiting database infrastructure, likely seeking sensitive data or internal communications for malicious purposes. The use of Turkish language strings suggests a potential linguistic link to the actor, though no definitive attribution can be made from this observation. Despite a temporary decrease in activity during February 2026, the threat actor's attacks resumed with intensity in March, indicating a persistent and potentially coordinated campaign targeting critical database systems.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Larva-26002 has demonstrated a consistent campaign pattern of attacking database servers, with peaks in activity during March 2026 despite a temporary lull. Their targeting appears to focus on systems with misconfigured accounts and unpatched vulnerabilities. Campaign activities are likely coordinated, using ICE Cloud as the primary toolset for scanning and exploitation. Recent operations suggest the actor is adaptative, pausing temporarily but resuming attacks with refined techniques.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on observed activities and toolchain usage. While Larva-26002's operations are well-documented, attribution remains speculative due to limited intelligence on the actor's origins or specific campaigns beyond their database targeting.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics