← Back to Feed

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN

July 24, 2026 · AhnLab ASEC · Severity: MEDIUM

AhnLab's ASEC discovered a targeted attack on MS-SQL servers where the Larva-26009 group deployed CoinMiner along with remote access tools and VPN, indicating a sophisticated campaign.

Key Takeaways

  • Larva-26009 threat actor targets MS-SQL servers with XMRig CoinMiner.
  • Attackers also install VShell and GotoHTTP for remote control.
  • Use of SoftEther VPN indicates advanced persistence and evasion.
☕ Buy a Coffee