Over 50,000 MS-SQL, PHPMyAdmin servers infected in Nansh0u campaign
#1
Quote:A fresh wave of attacks against MS-SQL and PHPMyAdmin servers has been detected across the globe, launched in the quest for cryptocurrency.
 
Over 50,000 servers belonging to organizations in healthcare, telecommunications, media, and IT have been infected, Guardicore Labs said on Wednesday.

Ophir Harpaz and Daniel Goldberg, researchers from Guardicore, said in a blog post that the so-called Nansh0u campaign is a sophisticated take on more primitive cryptocurrency mining attacks.
 
During the past two months, Guardicore has documented the compromise of Windows MS-SQL and PHPMyAdmin servers, originating on February 26, 2019. Over seven hundred victims per day were documented in some cases.
 
"The Nansh0u campaign is not a typical crypto-miner attack," the researchers say. "It uses techniques often seen in advanced persistent threats (APTs) such as fake certificates and privilege escalation exploits."

SOURCE: https://www.zdnet.com/article/over-50000...-campaign/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, Stefanos
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mullvad retires OpenVPN support on deskt...
OpenVPN gets the a...harlan4096 — 09:32
AdGuard VPN for Mac 2.8.2
AdGuard VPN for Ma...harlan4096 — 09:30
AMD FSR Redstone launched: ML-based Ups...
FSR Redstone’s ML Fr...harlan4096 — 09:29
(PC Game - Epic) Hogwarts Legacy (Dec 12...
  Hogwarts Legacy ...Mehdi — 18:56
AdGuard for Android 4.12.2
AdGuard for Androi...harlan4096 — 09:01

[-]
Birthdays
Today's Birthdays
avatar (43)ivyhuv
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>