← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Attack case against MS-SQL server installing ICE Cloud scanner (Larva-26002)
The Larva-26002 threat actor has been active in targeting mismanaged MS-SQL servers, exploiting vulnerabilities associated with the Bulk Copy Program (BCP) utility. This group is known for deploying various strains of ransomware, including Trigona and Mimic, and has evolved its tactics and tools over time. In 2026, they have notably adopted a Go language-written malware named ICE Cloud Client, a scanner designed to facilitate further malicious activities.
MITRE ATT&CK & Malware Families
Indicators of Compromise (5 / 10 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 0a9f2e2ff98e9f19428da79680e80b77 | — | 2026-03-23 | |
| FileHash-MD5 | 28847cb6859b8239f59cbf2b8f194770 | — | 2026-03-23 | |
| FileHash-MD5 | 5200410ec674184707b731b697154522 | — | 2026-03-23 | |
| FileHash-MD5 | 7fbbf16256c7c89d952fee47b70ea759 | — | 2026-03-23 | |
| FileHash-MD5 | 89bf428b2d9214a66e2ea78623e8b5c9 | — | 2026-03-23 |
References (1)