Gh0stCringe RAT Sets Its Sights on SQL Servers

Vulnerable Servers Are Attacked in Less Than 60 Seconds

The Gh0stCringe RAT, also known as CirenegRAT, is a Remote Access Trojan (RAT) that was discovered on hundreds of database servers around the world. The primary purpose of the RAT is to exfiltrate sensitive data from infected servers, and this is why one of its top features appears to be a keylogger. The SQL databases that the Gh0stCringe RAT goes after are likely to contain sensitive data, so if the criminals manage to get their hands on them, they could end up stealing passwords, emails, names, phones, and other information that can be sold on hacking forums.

Once the Gh0stCringe RAT is planted on a system successfully, it will run its payload in the background. While active, the malware will regularly transmit data to a remote command-and-control server. The good news is that the Gh0stCringe RAT appears to be a rather poorly coded project, and this is likely to mean that reputable antivirus products should have no problem identify and neutralizing this threat. The keylogger module of the Gh0stCringe RAT takes significant CPU resources, and system administrators will usually notice that there is something shady going on immediately.

The Gh0stCringe RAT is likely to propagate through brute force attacks. Researchers who analyzed infected servers report that many of them had traces of mining malware on them – proof that they their security was penetrated in the past. However, there does not seem to be a relation between the Gh0stCringe RAT and mining malware. Database servers can be protected from the Gh0stCringe RAT by ensuring that they are using strong login credentials, as well as the latest versions of all Internet-facing software and services. Last but not least, investing in reputable firewall and antivirus software is a great way to mitigate attacks from the Gh0stCringe RAT and similar malware.

March 21, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.