AhnLab said the Larva-26002 threat actor is continuing a multi-year campaign against poorly secured, internet-exposed Microsoft SQL Server systems, shifting from direct ransomware deployment to using compromised servers as part of a broader scanning operation. The group previously deployed Trigona and Mimic ransomware, abused the legitimate BCP utility to reconstruct malware from database contents, and installed remote access tools including AnyDesk, Teramind, and port-forwarding utilities. Researchers said the actor has repeatedly targeted servers with weak credentials and has continued to revisit previously compromised systems.
In the latest activity, the actor deployed the Go-based ICE Cloud malware family, including ICE Cloud Launcher and ICE Cloud Client, to authenticate with a command-and-control server, receive MSSQL scanning assignments, brute-force target servers with supplied credentials, and report successful logins back to the operator. AhnLab linked the campaign to earlier Mimic-related activity through Turkish-language strings and recurring artifacts such as the table name uGnzBdZbsi and format file FODsOZKgAU.txt, indicating continuity in tooling and tradecraft. The campaign suggests the group is building a distributed infrastructure to identify vulnerable database assets at scale, while defenders are being urged to strengthen passwords, rotate credentials, update security software, and restrict public database access with firewall controls.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
ASEC reported that Turkish-language strings in ICE Cloud, along with recurring artifacts such as the table name "uGnzBdZbsi" and format file "FODsOZKgAU.txt," align the 2026 campaign with earlier Mimic-related operations attributed to Larva-26002. This provided new technical details supporting continuity in the actor's tooling and tradecraft.
In 2026, Larva-26002 was observed using a Go-based malware family called ICE Cloud, including ICE Cloud Launcher and ICE Cloud Client, to authenticate to a C2 server, receive MSSQL scanning tasks, brute-force targets with supplied credentials, and report successful logins. The activity targeted improperly managed internet-exposed MS-SQL servers, including previously compromised systems, marking a move toward distributed scanning infrastructure rather than immediate ransomware deployment.
During 2025, the threat actor continued compromising exposed MS-SQL servers and added Teramind to its toolset. Reporting also links the group to use of a Rust-based scanner, indicating an expansion from ransomware deployment toward broader scanning and post-compromise operations.
In 2024, Larva-26002 began attacking poorly secured internet-exposed Microsoft SQL servers by abusing weak credentials. The actor deployed Trigona and Mimic ransomware, used the legitimate BCP utility to reconstruct malware on disk, and installed remote access tooling such as AnyDesk and port forwarders.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.