← Back to Feed

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN

July 24, 2026 · AhnLab ASEC · Severity: MEDIUM

The article details a case where the Larva-26009 threat actor targeted MS-SQL servers to install the XMRig CoinMiner. It highlights the persistent threat of cryptocurrency mining malware against database infrastructure.

Key Takeaways

  • AhnLab identified a targeted attack on MS-SQL servers by the Larva-26009 threat actor.
  • The attacker installed the XMRig CoinMiner to mine cryptocurrency on compromised servers.
  • This case underscores the ongoing risk of coinminer malware targeting database servers.
☕ Buy a Coffee