Larva-26009 is an intrusion cluster observed targeting MS-SQL server environments and using compromised systems for both remote access and cryptocurrency mining. In documented activity, the actor deployed XMRig CoinMiner after compromising MS-SQL servers and established multiple mechanisms for persistent control, including VShell, GotoHTTP, SoftEther VPN, web shells on IIS servers, Chrome Remote Desktop, Cloudflared, and hidden backdoor accounts. The actor has been observed abusing MS-SQL command execution to download and launch additional payloads. Persistence and post-compromise access included ASPX and PowerShell web shells, remote administration tooling, and covert account creation designed to reduce visibility to administrators. Larva-26009 also demonstrated defense evasion and post-exploitation tradecraft through encrypted payload staging, in-memory shellcode execution, and the use of patched legitimate binaries as loaders. Observed tooling and behavior indicate capabilities beyond simple cryptomining. Larva-26009 has shown credential-theft-related activity, including attempts to access sensitive system data and use of browser data theft tooling. The actor also used privilege-escalation utilities and internal network scanning tools, suggesting an ability to expand access after initial compromise. SoftEther VPN was configured in cascade mode, consistent with using victim infrastructure as part of a layered relay or command-and-control architecture that obscures upstream operator infrastructure. Overall, Larva-26009 appears to be a financially motivated actor focused on opportunistic compromise of exposed MS-SQL servers, combining cryptomining with durable remote access, stealthy persistence, credential access, privilege escalation, and internal reconnaissance.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted attacks against MS-SQL servers involving installation of XMRig CoinMiner and remote-control tools including VShell and GotoHTTP; the linked article title also indicates SoftEther VPN use.
Targets MS-SQL servers, likely via command execution after initial compromise, then installs remote access tooling, web shells, credential theft utilities, privilege escalation tools, scanners, proxy/tunneling components, XMRig coin mining payloads, and SoftEther VPN infrastructure to maintain control and obscure C2.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.