Over 50,000 MS-SQL, PHPMyAdmin servers infected in Nansh0u campaign
#1
Quote:A fresh wave of attacks against MS-SQL and PHPMyAdmin servers has been detected across the globe, launched in the quest for cryptocurrency.
 
Over 50,000 servers belonging to organizations in healthcare, telecommunications, media, and IT have been infected, Guardicore Labs said on Wednesday.

Ophir Harpaz and Daniel Goldberg, researchers from Guardicore, said in a blog post that the so-called Nansh0u campaign is a sophisticated take on more primitive cryptocurrency mining attacks.
 
During the past two months, Guardicore has documented the compromise of Windows MS-SQL and PHPMyAdmin servers, originating on February 26, 2019. Over seven hundred victims per day were documented in some cases.
 
"The Nansh0u campaign is not a typical crypto-miner attack," the researchers say. "It uses techniques often seen in advanced persistent threats (APTs) such as fake certificates and privilege escalation exploits."

SOURCE: https://www.zdnet.com/article/over-50000...-campaign/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, Stefanos
Reply


Messages In This Thread
Over 50,000 MS-SQL, PHPMyAdmin servers infected in Nansh0u campaign - by silversurfer - 29 May 19, 14:38

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Manjaro Linux 26.0.4 Build 260327
Manjaro Linux 26.0...harlan4096 — 09:46
K-Lite Codec Pack 19.6.0 / 19.6.3 Update
Changes in 19.6.3 ...harlan4096 — 09:45
AdGuard Browser Extension 5.3.1.7
AdGuard Browser Ex...harlan4096 — 09:44
uBOLite 2026.329.1951 (already available...
uBOLite 2026.329.1...harlan4096 — 09:43
Sandboxie Sandboxie-Plus v1.17.3 / 5.72....
Release v1.17.3 / ...harlan4096 — 09:42

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>