Hackers Target MS-SQL Servers to Deploy Ammyy Admin for Remote Access

Hackers Target MS-SQL Servers to Deploy Ammyy Admin for Remote Access

Sophisticated Cyberattack Targets Microsoft SQL Servers with Remote Access and Privilege Escalation Tools

A newly uncovered cyberattack campaign is actively targeting vulnerable Microsoft SQL (MS-SQL) servers, deploying remote access software and privilege escalation tools in a bid to gain persistent control over enterprise networks.

Security researchers have found that attackers are exploiting poorly secured MS-SQL instances—often those using default credentials or exposed management ports. Once inside, they install Ammyy Admin, a legitimate remote desktop application frequently abused for unauthorized access, alongside PetitPotato, a known privilege escalation utility.

These intrusions are designed to establish long-term access to corporate systems, enabling data exfiltration and lateral movement across internal environments. The campaign begins with scanning for accessible MS-SQL servers with weak configurations. Once a target is identified, the attackers execute reconnaissance commands to gather system details and customize their attack based on the environment.

Using command-line utilities, the adversaries then download and execute their payloads, demonstrating a high level of operational precision—indicative of a coordinated and well-resourced threat group.

According to researchers at Broadcom, the volume of these attacks has surged since early April 2025. The campaign appears to be industry-agnostic, affecting organizations in finance, healthcare, manufacturing, and more.

Though definitive attribution remains elusive, the tactics and targets are consistent with operations carried out by financially motivated threat actors.


Establishing Persistence: Multi-Layered Access Tactics

One of the more alarming aspects of this campaign is the focus on persistence. After the initial compromise, attackers activate Remote Desktop Protocol (RDP) services on the affected MS-SQL servers, offering them an alternative access route if their primary method is cut off.

In addition, they create new administrative user accounts—backdoors that remain functional even if malware components are identified and removed.

This layered persistence strategy reflects the sophistication of the threat and underscores the need for robust, continuous security monitoring that extends beyond traditional malware detection.

More Articles & Posts