SQLRat

MITRE ATT&CK: S0390 View on attack.mitre.org

Aliases: SQLRat

First seen
2018-10-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 12:45:18

Targeted industries: financial-services retail-and-hospitality

Context

SQLRat is malware that executes SQL scripts to avoid leaving traditional host artifacts. FIN7 has been observed using it.

Detection coverage

  • 369 Sigma rules

Malware & tools used

  • File Deletion (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Malicious File (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Scheduled Task (attack-pattern)
  • PowerShell (attack-pattern)

Used by threat actors

  • FIN7 (threat-actor)

Reports & references

  • flashpoint-intel.com — Fin7 Revisited Inside Astra Panel And Sqlrat Malware (report)
  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Sqlrat (report)
  • MITRE ATT&CK — S0390 (report)

External references