XiebroC2 Identified in MS-SQL Server Attack Cases
Oct. 1, 2025, 9:15 a.m.
Description
A recent attack on a poorly managed MS-SQL server involved the use of XiebroC2, an open-source C2 framework similar to CobaltStrike. The attackers exploited vulnerable credentials, installed JuicyPotato for privilege escalation, and then deployed XiebroC2 using PowerShell. XiebroC2 supports various features including remote control, information collection, and defense evasion across multiple platforms. The malware collects system information and connects to a C&C server for command execution. To protect against such attacks, administrators are advised to use complex passwords, regularly update them, keep security software current, and implement firewalls to restrict external access to publicly accessible database servers.
Tags
Date
- Created: Oct. 1, 2025, 7:36 a.m.
- Published: Oct. 1, 2025, 7:36 a.m.
- Modified: Oct. 1, 2025, 9:15 a.m.
Indicators
- 9351b5edec8401e5a0daf036a9e9b75954b4aeb4ffdf8dc30d9dedfa36fff004
- 0212bde3715a349a6b684dd54548638b5899be8d62a1e25559937e494e3cce54
- 183.196.14.213