Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft SQL servers under target, average ransom hits $740K+

Microsoft SQL servers under target, average ransom hits $740K+

OnMSFT Staff OnMSFT Staff
September 4, 2023
2 min read

In this article

  • How does it work?
  • Attack process
  • How to protect?

The campaign is dubbed “DB#JAMMER,” it involves threat actors exploiting vulnerabilities in poorly secured Microsoft SQL servers to deliver Cobalt Strike and a ransomware strain called FreeWorld.

How does it work?

Hackers use different tools, like programs to find information, software that can take control of your computer remotely [Remote Access Trojan (RAT) payloads], and some tools to break into systems and steal passwords. Finally, they use a ransomware program to lock up your computer and demand money to unlock it.

Attack process

  • Initial access is gained through brute-forcing the MS SQL server.
  • The attackers then enumerate the database and leverage the xp_cmdshell configuration option to run shell commands and conduct surveillance.
  • Steps are taken to impair the system firewall and establish persistence by connecting to a remote SMB share to transfer files and install malicious tools such as Cobalt Strike.
  • AnyDesk software is distributed, followed by the deployment of the FreeWorld ransomware.
  • Lateral movement within the victim’s network is also attempted.

This year, there have been many ransomware attacks, but people are paying less often to get their files back, to a record low of 34%, but when they do, they reach $740,144, up 126% from Q1 2023.

How to protect?

Here are some tips for protecting your Microsoft SQL servers from ransomware attacks:

  • Use strong passwords and keep them up to date.
  • Enable two-factor authentication.
  • Keep your SQL Server software up-to-date.
  • Safeguard your SQL Server servers with a firewall to prevent unauthorized access.
  • Employ intrusion detection and prevention systems to identify and thwart malicious actions.
  • Back up your data regularly and keep your backups offline.
  • Have a plan in place to recover from a ransomware attack.

This information underscores the importance of robust cybersecurity measures, such as securing Microsoft SQL servers with strong passwords, regularly updating software and security patches, and maintaining reliable backups to mitigate the impact of ransomware attacks. They pay a lot more.

via HackerNews

Related

Share this article:
Previous Article Here is the full list of all Forza Motorsport launch day racetracks Next Article Microsoft September 21 event: Uncovering important leaks you can’t miss

Related Articles

Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS

April 4, 2026

New Ryzen 9 9950X3D2 loses performance on air cooling

April 4, 2026

Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense

April 4, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling
  • Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense
  • ELSA Launches GigaIO Gryf Portable AI System with Modular Design
  • NASA Artemis II astronauts face Outlook issues in space as mission hits unexpected software glitch

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Red Magic 11 runs PC games like GTA 5 and Cyberpunk 2077 on Android at 60 FPS
  • New Ryzen 9 9950X3D2 loses performance on air cooling
  • Legion Go 2 now costs $1,999 at Best Buy, pricing no longer makes sense
  • ELSA Launches GigaIO Gryf Portable AI System with Modular Design
  • NASA Artemis II astronauts face Outlook issues in space as mission hits unexpected software glitch

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy