Vollgar is a coin-mining malware family associated with attacks on poorly secured Microsoft SQL Server environments. It has been observed alongside other MS-SQL-targeting miners such as KingMiner and Lemon Duck, and is commonly deployed after attackers obtain administrative access to internet-exposed database servers. Reported intrusion patterns indicate operators identify exposed MS-SQL services, then use brute-force or dictionary attacks against weak administrator credentials before using SQL-enabled command execution paths to install mining payloads on compromised Windows hosts. Vollgar is therefore best characterized as part of the ecosystem of opportunistic cryptomining campaigns that abuse weakly managed database infrastructure for unauthorized resource consumption.
Operationally, Vollgar is linked to post-compromise deployment on MS-SQL servers rather than to a distinct exploit chain of its own in the supplied facts. It appears in infection histories on servers later used for additional malware activity, indicating that compromised database servers may be repeatedly monetized by multiple actors or through successive payload deployment. The malware’s role in these incidents is unauthorized cryptocurrency mining, and its presence is a marker of weak credential hygiene and exposed administrative services in enterprise environments running Microsoft SQL Server on Windows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CoinMiner campaign targeting exposed MS-SQL servers via brute force to deploy mining payloads.
CoinMiner malware mentioned as another infection found on compromised systems, distributed through brute force attacks against servers.
A named coin-mining malware observed as a payload dropped after MS-SQL server compromise.
CoinMiner malware targeting MS-SQL servers; the article notes detection logs of Vollgar on the targeted system, suggesting prior compromise tied to weak account credential management.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.