← Back to Feed
Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN
July 24, 2026 · AhnLab ASEC · Severity: MEDIUM
AhnLab's ASEC discovered a targeted attack on MS-SQL servers where the Larva-26009 group deployed CoinMiner along with remote access tools and VPN, indicating a sophisticated campaign.
Key Takeaways
- Larva-26009 threat actor targets MS-SQL servers with XMRig CoinMiner.
- Attackers also install VShell and GotoHTTP for remote control.
- Use of SoftEther VPN indicates advanced persistence and evasion.