Maggie

Malware type
backdoor
Profile updated
2026-07-07 13:10:34

Targeted industries: technology-and-telecommunications financial-services

Context

According to DCSO, this malware is written as a Extended Stored Procedure for a MSSQL server. The backdoor has capabilities to bruteforce logins to other MSSQL servers, adding a special hardcoded backdoor user in the case of successfully bruteforcing admin logins.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Maggie_Auto (yara-rule)

Reports & references

  • sentinelone.com — Wip19 Espionage New Chinese Apt Targets It Service Providers And Telcos With Signed Malware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Maggie (report)
  • medium.com — Tracking Down Maggie 4D889872513D (report)
  • medium.com — Mssql Meet Maggie 898773Df3B01 (report)

External references