Larva-26002 is a threat actor targeting exposed MS-SQL servers to deploy Trigona ransomware and remote access tools.
Analyst brief
Larva-26002 is a threat actor targeting improperly managed MS-SQL servers through brute force and dictionary attacks. They distribute Trigona and Mimic ransomware, leverage the Bulk Copy Program (BCP) for exploitation, and install remote access tools such as AnyDesk and Teramind. Additionally, the actor deploys scanner malware like the Go-based ICE Cloud Client and a Rust-based scanner to map the environment. Defenders should prioritize MS-SQL server hardening, enforce strong credential policies, and monitor for suspicious BCP usage or unauthorized remote access tool installations.
Larva-26002
unknown
Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks. The actor has distributed Trigona and Mimic ransomware, utilizing the Bulk Copy Program for exploitation and installing remote access tools like AnyDesk and Teramind. In their attacks, they also deploy scanner malware, including ICE Cloud Client written in Go and a Rust-based scanner. After compromising systems, they execute commands to gather information about the infected environment.