Summary:
As per researchers, poorly secured and internet-exposed Microsoft SQL (MS-SQL) servers are being targeted by attackers to deploy Trigona ransomware payloads and encrypt all files. Attackers are exploiting weak login credentials such as easy-to-guess passwords to gain access to MS-SQL servers. The malware is employed to collect system data, modify the configuration of the compromised account, and elevate privileges to LocalSystem by exploiting a vulnerability in the Windows Secondary Logon Service.[/subscribe_to_unlock_form]
Summary:
As per researchers, poorly secured and internet-exposed Microsoft SQL (MS-SQL) servers are being targeted by attackers to deploy Trigona ransomware payloads and encrypt all files. Attackers are exploiting weak login credentials such as easy-to-guess passwords to gain access to MS-SQL servers. The malware is employed to collect system data, modify the configuration of the compromised account, and elevate privileges to LocalSystem by exploiting a vulnerability in the Windows Secondary Logon Service.[emaillocker id="1283"]
After gaining initial access to a server, the attackers install CLR Shell malware, as identified by cybersecurity experts. The CLR Shell is designed as a CLR assembly to execute commands received from attackers and conduct malicious activities. The CLR Shell malware includes a routine that exploits privilege escalation vulnerabilities. This is likely due to the high privileges required by Trigona, as it operates as a service. The attackers proceed to install and launch a dropper malware as the svcservice.exe service, which they use to initiate the Trigona ransomware as svchost.exe. To ensure persistence, the attackers configure a Windows autorun key to launch the Trigona ransomware binary automatically on each system restart. The malware disables system recovery and deletes Windows Volume Shadow copies before encrypting the system and deploying ransom notes, rendering recovery impossible without the decryption key. Trigona encrypts all files on victims' devices, except for those in specific directories, such as Windows and Program Files.
The threat group alleges that they steal sensitive documents before encrypting them and add them to their dark web leak site. The ransomware also adds the “._locked” extension to encrypted files and includes the campaign ID, encrypted decryption key, and victim ID (company name) in each locked file. Trigona creates ransom notes in each folder, which contain attack details, a link to the Trigona Tor negotiation website, and an authorization key required for accessing the negotiation site. Since the beginning of the year, the Trigona ransomware gang has been responsible for a steady flow of attacks, with at least 190 reported incidents on the ID Ransomware platform.
Poorly managed MS-SQL servers are often targeted by attackers who exploit vulnerabilities such as weak account credentials, using brute-force or dictionary attacks to gain unauthorized access. To safeguard database servers against brute force and dictionary attacks, administrators should utilize strong passwords that are not easily guessed, and regularly update them. To prevent malware infections, it is recommended to update V3 to the latest version available.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]