Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors larva-26002

Description

During the first quarter of 2026, Windows-based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language strings and C&C-based scanning capabilities. This tool attempted MS-SQL authentication using predefined credentials. Attack methods primarily consisted of brute force attacks, dictionary attacks, and exploitation of unpatched systems with misconfigured accounts stemming from inadequate account management practices.

AI Analysis

· 1 week ago

Executive Summary

Larva-26002 is a threat actor targeting Windows-based MS-SQL and MySQL database servers through malicious attacks involving credential brute force, dictionary attacks, and exploitation of unpatched systems. The actor deploys a Go-based scanner named ICE Cloud to access these systems using predefined credentials and Turkish language strings in their toolset.

Goals & Targeting

Larva-26002 appears to target sectors that maintain sensitive databases, such as financial institutions, healthcare providers, and critical infrastructure organizations. Their focus on MS-SQL and MySQL suggests an interest in data extraction and potential disruption of operational systems. The actor's geographic targeting is currently undefined due to limited intelligence but may be focused on regions with weaker cybersecurity practices or underpatched systems. The use of predefined credentials indicates a desire to exploit poor account management practices rather than advanced technical vulnerabilities. Their goal likely involves data theft, espionage, or sabotage.

Enhanced Description

Larva-26002 primarily focuses on compromising database servers, leveraging a combination of brute force, dictionary attacks, and exploitation techniques targeting misconfigured and unpatched systems. The actor employs tools such as BCP, curl, bitsadmin, and PowerShell to deploy their Go-based ICE Cloud scanner. This tool identifies MS-SQL authentication vulnerabilities using predefined credentials and attempts unauthorized access. Larva-26002's activities are characterized by their systematic approach to scanning and exploiting database infrastructure, likely seeking sensitive data or internal communications for malicious purposes. The use of Turkish language strings suggests a potential linguistic link to the actor, though no definitive attribution can be made from this observation. Despite a temporary decrease in activity during February 2026, the threat actor's attacks resumed with intensity in March, indicating a persistent and potentially coordinated campaign targeting critical database systems.

Key Capabilities

  • Credential brute force
  • Dictionary attacks
  • Exploitation of unpatched systems
  • Use of toolset (BCP, curl, bitsadmin, PowerShell)
  • Deployment of Go-based ICE Cloud scanner
  • C2 communication via Turkish language strings

MITRE ATT&CK Tactics

Credential Access
Lateral Movement
Exfiltration

ATT&CK Techniques

T1064.001 - Brute Force: Predefined Credential
T1566.003 - Compromise Accounts Using Cred Dumping Tools
T1078.001 - Application Layer Attack Frameworks

Software / Tooling

ICE Cloud (Go-based scanner)
BCP
curl
bitsadmin
PowerShell

Campaigns & Victims

Larva-26002 has demonstrated a consistent campaign pattern of attacking database servers, with peaks in activity during March 2026 despite a temporary lull. Their targeting appears to focus on systems with misconfigured accounts and unpatched vulnerabilities. Campaign activities are likely coordinated, using ICE Cloud as the primary toolset for scanning and exploitation. Recent operations suggest the actor is adaptative, pausing temporarily but resuming attacks with refined techniques.

IOC Patterns

  • Spear-phishing emails containing malicious scripts targeting database administrators
  • Use of Turkish language strings in C2 communication channels
  • Script-based network scanning for MS-SQL and MySQL services
  • Brute force attempts against MS-SQL authentication
  • Use of predefined credential lists for attacks
  • C2 activity over HTTPS or encrypted channels

Recommended Actions

  • Harden database server configurations and patch promptly
  • Monitor network traffic for unusual scanning patterns
  • Implement multi-factor authentication for critical accounts
  • Deploy endpoint detection tools to identify malicious scripts
  • Review and update account management practices to eliminate weak passwords
  • Set up network-based monitoring for known C2 IP ranges

Suggested Tags

Hacker
Database compromise
Credential exploitation
SMB attacks
Cyber Espionage

Confidence Assessment

The analysis is based on observed activities and toolchain usage. While Larva-26002's operations are well-documented, attribution remains speculative due to limited intelligence on the actor's origins or specific campaigns beyond their database targeting.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
Hacker
Database compromise
Credential exploitation
SMB attacks
Cyber Espionage

Details

Type
Unknown
Confidence
55%
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.