← Back to Feed
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN
July 24, 2026 · AhnLab ASEC · Severity: MEDIUM
The article details a case where the Larva-26009 threat actor targeted MS-SQL servers to install the XMRig CoinMiner. It highlights the persistent threat of cryptocurrency mining malware against database infrastructure.
Key Takeaways
- AhnLab identified a targeted attack on MS-SQL servers by the Larva-26009 threat actor.
- The attacker installed the XMRig CoinMiner to mine cryptocurrency on compromised servers.
- This case underscores the ongoing risk of coinminer malware targeting database servers.