A threat actor exploited an SQL injection flaw in a web page at a technology-sector organization, compromising an endpoint running IIS and Microsoft SQL Server and then carrying out extensive post-exploitation activity. Huntress reported the attacker used base64-encoded PowerShell for payload delivery, ran reconnaissance including tasklist /svc, and exfiltrated process information to an OAST domain. The actor then enabled Remote Desktop Services, created a new local administrator account named adminweb2$, and attempted to disable Windows Defender to retain access and reduce detection.
The intrusion escalated into broad persistence and monetization efforts on the same host. The attacker installed known BadIIS modules using appcmd.exe, downloaded the XMRig cryptocurrency miner, hid miner-related files with attrib.exe, and used nssm.exe to keep the miner running persistently. Additional payloads included PowerShell and batch files such as qdcjoke1.2.ps1, c_joke1.2.ps1, and qd_tjoke.bat, along with CnCrypt Protect, likely for defense evasion. Huntress said the case stood out for the volume of system changes made after the initial compromise and warned that remediation must address the original SQL injection weakness to prevent re-entry.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Huntress published a report detailing the June 26 intrusion, including the SQL injection vector, post-compromise persistence steps, BadIIS installation, XMRig deployment, and additional payloads such as PowerShell scripts, batch files, and CnCrypt Protect.
Following the SQL injection compromise, the actor used base64-encoded PowerShell, performed reconnaissance, enabled Remote Desktop Services, created a local administrator account named adminweb2$, attempted to disable Windows Defender, installed BadIIS modules, and deployed XMRig with persistence via nssm.exe.
On June 26, a threat actor exploited an SQL injection flaw in a web page hosted on an endpoint running IIS and Microsoft SQL Server at a technology-sector organization, gaining initial access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.