Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
Menu
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
  1. Home
  2. News
  3. Surge in malware attacks on MSSQL server up 84%

Surge in malware attacks on MSSQL server up 84%

Devesh Beri Devesh Beri
July 12, 2023
2 min read

Over the past six months, there has been a significant increase in malware attacks targeting Microsoft SQL (MSSQL) Server as an intrusion method. Security experts have observed a shift in hacker tactics, moving away from previously blocked techniques.

Just yesterday, Microsoft addressed the malicious exploitation of certified Windows drivers.

According to the report from ESET, a cybersecurity firm, the number of MSSQL attacks has risen by 84% between the second half of 2022 and the first half of 2023.

This surge in attacks exploiting MSSQL as a vector can be attributed to Microsoft’s decision to block Virtual Basic for Applications (VBA) macros in Office documents by default last year. For years, cybersecurity professionals had advocated for stricter default controls on VBA macros, and Microsoft finally implemented these changes.

Historically, cybercriminals frequently used VBA macros in Office documents to embed malware distributed through phishing campaigns. However, after Microsoft blocked this attack avenue, researchers observed a clear increase in attacks utilizing OneNote as an alternative vector. Malicious actors behind malware like Emotet started exploiting .one files to deceive users into executing malicious scripts, moving away from their previous reliance on VBA macros.

ESET’s report highlights that Microsoft’s actions to block VBA macros and enhance OneNote’s security have led cybercriminals to explore other intrusion vectors, particularly MSSQL, for future attacks. MSSQL is a widely-used solution for regional database management. When MSSQL servers are exposed to the internet, they become attractive targets for hackers. These servers can be accessed via port 1433, which exposes them to brute-force password-guessing attempts by threat actors.

ESET emphasizes that organizations with weak passwords or improperly managed servers are especially vulnerable. They reference an AhnLab report from April, which examined a case of ransomware installed on MSSQL servers due to easily guessable credentials.

Telemetry data reveals a staggering 1.7 billion failed password-guessing attempts against MSSQL from December 2022 to May 2023.

While attacks on MSSQL have increased, there has been a decline in brute-force attempts on other commonly targeted attack vectors. For instance, attacks on Remote Desktop Protocol (RDP), often exploited for malware like RDStealer, dropped by 22% from 17.9 billion to 15.8 billion during the same period.

Brute-force attacks are among the preferred password-cracking techniques employed by hackers. They rely on weak password strategies, such as password reuse or the absence of complexity controls within organizations.

Ladislav Janko, a senior detection engineer at ESET, advises database administrators to consider the security advantages of Windows Authentication mode when setting up the database engine. In this mode, SQL Server Authentication is disabled, and users must connect through their Windows user account, which can be protected with an account lockout policy to halt brute-force attacks effectively.

If using mixed mode is unavoidable, organizations should ensure strong passwords and place the database behind a firewall or VPN, if feasible.

via ITPro

Related

Share this article:
Previous Article Microsoft, KPMG enhance AI collaboration with $12 billion in prospective growth opportunities Next Article CMA could launch new investigation if Activision Blizzard deal is restructured

Related Articles

Discord Nitro May Add Xbox Game Pass Starter Edition With 50+ Games and Cloud Gaming Access

April 24, 2026

Microsoft Drops ‘Microsoft Gaming’ Name, Brings Back Xbox Identity

April 24, 2026

Intel 14A Wins Tesla Deal, More Customers Show Interest

April 24, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Discord Nitro May Add Xbox Game Pass Starter Edition With 50+ Games and Cloud Gaming Access
  • Microsoft Drops ‘Microsoft Gaming’ Name, Brings Back Xbox Identity
  • Intel 14A Wins Tesla Deal, More Customers Show Interest
  • Token-Based Pricing Disrupts AI Market as Groq Outpaces NVIDIA on Cost and Speed
  • Samsung and Kingston Raise SSD Prices Again as Costs Climb Over 10%

Recent Comments

  1. William on NZXT Responds to RTX 5090 Leak Claim, Disputes Redditor’s Version of Events
  2. Jenny Jones on Microsoft Publisher Will Shut Down in October 2026 and Users Are Not Happy
  3. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  4. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Discord Nitro May Add Xbox Game Pass Starter Edition With 50+ Games and Cloud Gaming Access
  • Microsoft Drops ‘Microsoft Gaming’ Name, Brings Back Xbox Identity
  • Intel 14A Wins Tesla Deal, More Customers Show Interest
  • Token-Based Pricing Disrupts AI Market as Groq Outpaces NVIDIA on Cost and Speed
  • Samsung and Kingston Raise SSD Prices Again as Costs Climb Over 10%

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy