Over 50,000 MS-SQL, PHPMyAdmin servers infected in Nansh0u campaign
#1
Quote:A fresh wave of attacks against MS-SQL and PHPMyAdmin servers has been detected across the globe, launched in the quest for cryptocurrency.
 
Over 50,000 servers belonging to organizations in healthcare, telecommunications, media, and IT have been infected, Guardicore Labs said on Wednesday.

Ophir Harpaz and Daniel Goldberg, researchers from Guardicore, said in a blog post that the so-called Nansh0u campaign is a sophisticated take on more primitive cryptocurrency mining attacks.
 
During the past two months, Guardicore has documented the compromise of Windows MS-SQL and PHPMyAdmin servers, originating on February 26, 2019. Over seven hundred victims per day were documented in some cases.
 
"The Nansh0u campaign is not a typical crypto-miner attack," the researchers say. "It uses techniques often seen in advanced persistent threats (APTs) such as fake certificates and privilege escalation exploits."

SOURCE: https://www.zdnet.com/article/over-50000...-campaign/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, Stefanos
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
WhatsApp Adds Security Warning Before Us...
WhatsApp has intro...harlan4096 — 08:21
uBOLite 2026.625.1633
uBOLite 2026.625.1...harlan4096 — 07:35
7-Zip 26.02
7-Zip 26.02 Wha...harlan4096 — 07:23
AMD to bring back Ryzen 7 5800X3D as AM...
AMD has officially r...harlan4096 — 07:12
Windows Secure Boot Certificate Expiry E...
Microsoft’s long-p...harlan4096 — 07:04

[-]
Birthdays
Today's Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>