Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Threat Actors Hijacking MS-SQL Server to Deploy XiebroC2 Framework

Threat Actors Hijacking MS-SQL Server to Deploy XiebroC2 Framework

Posted on September 30, 2025September 30, 2025 By CWS

A complicated assault marketing campaign concentrating on improperly managed Microsoft SQL servers has emerged, deploying the XiebroC2 command and management framework to determine persistent entry to compromised techniques.

The assault leverages susceptible credentials on publicly accessible database servers, permitting risk actors to achieve preliminary foothold and escalate privileges by a multi-stage deployment course of.

XiebroC2, a publicly accessible C2 framework much like CobaltStrike, gives attackers with complete distant management capabilities together with info gathering, protection evasion, and system manipulation.

The marketing campaign follows a predictable sample noticed in MS-SQL server assaults, starting with credential-based intrusions and progressing to coin mining operations.

Nevertheless, the mixing of XiebroC2 represents a major escalation in assault sophistication, because the framework helps cross-platform operations throughout Home windows, Linux, and macOS environments.

The framework’s open-source nature and intensive function set make it a gorgeous various to business penetration testing instruments, providing attackers capabilities similar to reverse shells, file administration, course of management, and community monitoring with out the related prices.

ASEC analysts recognized the malware throughout routine monitoring of assaults concentrating on MS-SQL servers, confirming the deployment of XiebroC2 alongside conventional coin mining payloads.

The framework’s implant element, written in Go programming language, demonstrates superior methods for evading detection whereas sustaining persistent communication with command and management infrastructure.

XiebroC2’s GitHub web page (Supply – ASEC)

The assault methodology highlights the continuing vulnerability of database servers that lack correct safety hardening and entry controls.

Privilege Escalation By JuicyPotato Exploitation

The assault chain demonstrates a methodical strategy to privilege escalation by the deployment of JuicyPotato, a well-documented exploit device that abuses Home windows token privileges.

Following profitable authentication to the goal MS-SQL server, attackers encounter the inherent limitation of service account privileges, which usually function with restricted entry rights by design.

To beat this constraint, the risk actors make the most of JuicyPotato to take advantage of particular token privileges inside the presently working course of account, successfully elevating their entry from service-level to administrative permissions.

The privilege escalation method capitalizes on the impersonation privileges usually granted to service accounts, permitting the exploit to abuse these permissions and spawn processes with elevated rights.

As soon as JuicyPotato efficiently escalates privileges, attackers proceed to obtain and execute the XiebroC2 framework utilizing PowerShell instructions.

This strategy ensures that subsequent malicious actions function with ample privileges to switch system configurations, set up further payloads, and set up persistent backdoors.

MS-SQL service downloading XiebroC2 (Supply – ASEC)

The configuration knowledge reveals the framework’s skill to gather complete system info together with course of identifiers, {hardware} identifiers, working directories, and consumer credentials earlier than establishing encrypted communication channels with the command and management server positioned at IP deal with 1.94.185.235 on port 8433.

Observe us on Google Information, LinkedIn, and X to Get Extra Immediate Updates, Set CSN as a Most well-liked Supply in Google.

Cyber Security News Tags:Actors, Deploy, Framework, Hijacking, MSSQL, Server, Threat, XiebroC2

Post navigation

Previous Post: $50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections
Next Post: CISA Warns of Libraesva ESG Command Injection Vulnerability Actively Exploited in Attacks

Related Posts

Securing Generative AI – Mitigating Data Leakage Risks Securing Generative AI – Mitigating Data Leakage Risks Cyber Security News
Linux Kernel netfilter Vulnerability Let Attackers Escalate Privileges Linux Kernel netfilter Vulnerability Let Attackers Escalate Privileges Cyber Security News
Malicious NPM Package with 56K Downloads Steals WhatsApp Messages Malicious NPM Package with 56K Downloads Steals WhatsApp Messages Cyber Security News
Google Chrome May Soon Turn Webpages Into Podcasts With AI Audio Overviews Google Chrome May Soon Turn Webpages Into Podcasts With AI Audio Overviews Cyber Security News
Microsoft Warns of OneDrive Bug that Causes Searches to Appear Blank Microsoft Warns of OneDrive Bug that Causes Searches to Appear Blank Cyber Security News
Palo Alto Networks PAN-OS Vulnerability Enables Admin to Execute Root User Actions Palo Alto Networks PAN-OS Vulnerability Enables Admin to Execute Root User Actions Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Intel and AMD Address 70 Security Weaknesses on Patch Tuesday
  • GemStuffer Exploits RubyGems for U.K. Council Data Exfiltration
  • Critical Exim GnuTLS Flaw Exposes Servers to Attacks
  • RubyGems Halts Registrations Amid Security Threat
  • Android Enhances Security with New Intrusion Logging

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Intel and AMD Address 70 Security Weaknesses on Patch Tuesday
  • GemStuffer Exploits RubyGems for U.K. Council Data Exfiltration
  • Critical Exim GnuTLS Flaw Exposes Servers to Attacks
  • RubyGems Halts Registrations Amid Security Threat
  • Android Enhances Security with New Intrusion Logging

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark