Larva-26002 is a persistent threat actor focused on compromising poorly secured, internet-exposed Microsoft SQL Server systems. Activity attributed to this cluster has been observed since at least 2024 and shows continuity in tooling and tradecraft through 2026. The actor initially monetized access by deploying Trigona and Mimic ransomware on compromised MS-SQL servers, then evolved toward using those systems as a distributed scanning infrastructure to identify additional vulnerable database servers. The group commonly gains initial access by targeting exposed MS-SQL services protected by weak credentials, including brute-force or dictionary-style password attacks. After obtaining access, the actor performs basic host profiling and abuses legitimate administrative utilities associated with MS-SQL to write payloads to disk. When that method is unsuccessful, the actor falls back to native Windows download mechanisms and PowerShell-based retrieval. Larva-26002 has also established remote access and operational persistence through remote administration and monitoring tools, including AnyDesk and Teramind, and has used port forwarding to enable follow-on remote access. By 2025, the actor was operating a Rust-based scanner, and by 2026 it had transitioned to a Go-based malware family referred to as ICE Cloud Client, delivered by an ICE Cloud Launcher component. This tooling authenticates to command-and-control infrastructure, retrieves scanning tasks and credential sets, attempts authentication against additional MS-SQL targets, and reports successful compromises back to the operator. The campaign demonstrates a shift from direct ransomware deployment to post-compromise reuse of victim infrastructure for reconnaissance and credential-based scanning at scale. Turkish-language strings embedded in later tooling link the 2026 activity to the earlier Mimic-related operations, indicating likely operator continuity. Larva-26002 is therefore best characterized as an opportunistic intrusion actor targeting exposed database infrastructure, with demonstrated ransomware deployment, credential attacks, remote administration abuse, and large-scale scanning operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.