Skip-2.0

Description

(ESET) This backdoor targets MSSQL Server 11 and 12, allowing the attacker to connect stealthily to any MSSQL account by using a magic password – while automatically hiding these connections from the logs. Such a backdoor could allow an attacker to stealthily copy, modify or delete database content. This could be used, for example, to manipulate in-game currencies for financial gain. In-game currency database manipulations by Winnti operators have already been reported.

Names

Name
Skip-2.0

Category

Malware

Type

  • Backdoor
  • Exfiltration

Information

Malpedia

Other Information

Uuid

39b1fa4d-de40-4fb5-86e5-f50cd9be3b7d

Last Card Change

2021-04-24