Threat intelligence report · AlienVault OTX

Threat Actors Achieve Persistence After SQL Injection

Threat actors gaining initial access through SQL injection exploited a web application vulnerability in a technology sector organization. After compromising an MSSQL instance via inadequate input validation, the attackers deployed base64-encoded PowerShell scripts to conduct reconnaissance using tasklist commands and exfiltrated results to an external server. They established persistence by enabling Remote Desktop Services, creating an administratively privileged user account named adminweb2$, and disabling Windows Defender. The attackers installed BadIIS modules for SEO fraud, deployed XMRig cryptocurrency miner with hidden file attributes, and utilized service creation tools. Multiple PowerShell scripts and batch files were downloaded throughout the attack to facilitate various malicious operations and maintain access.

· unknown severity · unattributed attribution

Evidence and provenance

Original source
AlienVault OTX report ↗
Published
2026-07-13T20:52:22.780000Z
Confidence basis
No actor match
Record ID
54f5e4305fb9afbabca6

Affected sectors

technology

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.