Maggie
- Malware type
- backdoor
- Profile updated
- 2026-07-07 13:10:34
Targeted industries: technology-and-telecommunications financial-services
Context
According to DCSO, this malware is written as a Extended Stored Procedure for a MSSQL server. The backdoor has capabilities to bruteforce logins to other MSSQL servers, adding a special hardcoded backdoor user in the case of successfully bruteforcing admin logins.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Maggie_Auto (yara-rule)
Reports & references
- sentinelone.com — Wip19 Espionage New Chinese Apt Targets It Service Providers And Telcos With Signed Malware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Maggie (report)
- medium.com — Tracking Down Maggie 4D889872513D (report)
- medium.com — Mssql Meet Maggie 898773Df3B01 (report)