Larva-26009
Larva-26009 targets MS-SQL servers and has been observed installing the XMRig CoinMiner.
Financially motivated Larva-26009 targets MS-SQL servers to deploy XMRig CoinMiner for cryptocurrency mining.
Larva-26009 is a financially motivated threat actor of unknown origin. It primarily targets MS-SQL servers. The attacker has been observed installing XMRig CoinMiner to exploit victim resources for cryptocurrency mining. Defenders should monitor for brute-force attacks against MS-SQL servers, suspicious SQL queries, and C2 communications associated with XMRig.
Larva-26009 targets MS-SQL servers and has been observed installing the XMRig CoinMiner.
Larva-26009 primarily targets MS-SQL servers.
Larva-26009 installs XMRig CoinMiner to exploit victim resources for cryptocurrency mining.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.