Vietnam Newsroom & Threat Intelligence
Clear sources · Careful assessments
NOTEDo not attribute a ransomware family from a file extension or a single ransom note.Vietnam time · UTC+7
Technical analysis

Ransomware .PIZ via MSSQL: comparing the attack chain with CyRadar's source

Correcting attribution in the archive: separate CyRadar's MSSQL report from .PIZ, AnyDesk and Safe Mode hypotheses; retain log checklists and technical material for comparison.

Updated: · Vietnam time (UTC+7)

Illustration of a SQL server and access review, not incident logs.
Illustration from No.Ransomware.VN • Not evidence from an incident.
Not independently verified

CyRadar's 08/09/2026 source page has been reviewed. It does not confirm .PIZ / AnyDesk / Safe Mode in the archive. Those observations remain Unconfirmed; the ATT&CK table is not confirmation that behaviors occurred.

Original title (English translation): Ransomware .PIZ via MSSQL: from brute force to Safe Mode and encryption

Source: No.Ransomware.VN · Original date:

Original URL: https://no.ransomware.vn/tin-ransomware/ransomware-piz-mssql-cyradar-case-study/

The original is retained for comparison. The update history below records changes to sources, scope and assessments.

Evidence / published sources

The linked CyRadar report describes MSSQL intrusion through a highly privileged SQL account, SQL Server Agent Job persistence and PowerShell/CLR execution layers over several weeks. These are researcher findings, not reproduced by Ransomware.VN on samples.

The reviewed source does not support attribution of .PIZ, AnyDesk, Safe Mode or approximately 38,000 brute-force attempts to that report. Ransomware.VN withdraws that source attribution. The archived infographic's provenance also lacks independent corroboration.

Technical assessment

The passages below are the pre-consolidation No.Ransomware.VN analysis, relabeled for comparison. Incident-chain descriptions are unverified archive assessments. Questions about SQL logins, xp_cmdshell, CLR, remote tools and logs are investigative directions, not conclusions for a real case.

Do not run source commands or samples on production systems. Examine permissions, configurations and artifacts in authorized environments; preserve originals, timelines and evidence sources.

Archived analysis • Incident-chain descriptions not independently verified. This content is retained for comparison, not as confirmation of an incident.

Ransomware campaign analysis infographic attributed to CyRadar
The archive credits CyRadar for the image. Ransomware.VN has not independently verified its provenance and does not use it to prove the .PIZ chain. No.Ransomware.VN only improved display resolution/sharpness; it did not add a TUNGTEK signature that could misrepresent authorship.

The key point of this case is not the extension .piz, but the attack chain before encryption. The indicators suggest scanning, password guessing, SQL Server execution capabilities, remote-control setup and a deliberate Safe Mode boot to weaken protections before mass encryption.

Scanning~38.000SQL brute-force attempts sa
Entry pointMSSQL / RDPdirectly exposed to the Internet
RemoteAnyDeskinstalled as a Service + Startup
Impact.pizmass data encryption
Do not identify ransomware solely from the extension .PIZ. Extensions may be reused by malware, variants or campaigns. Family identification needs ransom notes, file structure, markers/headers, encryptor behavior, samples, hashes, mutexes, paths, logs and infrastructure. This article therefore uses the neutral description: “ransomware using the .PIZ extension in the case published by CyRadar”.

The archived infographic, attributed to CyRadar with provenance not yet checked, divides the incident into five stages. It fits a hands-on-keyboard model: interaction with the server, control of privileges, installation of access tools and environment preparation before impact, rather than immediate encryptor deployment.

Stage 1

Scanning & information gathering

28/08 – 16/09/2026. Management services such as RDP/MSSQL/SMB were exposed to the Internet. The old No.Ransomware.VN version reports about 38,000 SQL brute-force attempts (not independently verified) targeting account sa, with indicators related to xp_cmdshell and OLE Automation.

Stage 2

Initial access & privilege escalation

23/09, 22:53 – 23:58. According to the original source, the attacker configured a SQL CLR Assembly, created unusual services and obtained the privilege context NT AUTHORITY\SYSTEM. This marks a transition from SQL privileges to operating-system control.

Stage 3

Persistence & control channel setup

23 – 24/09. An Administrator RDP login came from an external IP, followed by AnyDesk installed as a Service and Startup entry. Abused legitimate remote-access traffic can blend with routine technical support.

Stage 4

Defense evasion

24/09, 00:35 – 01:08. The machine booted into Safe Mode, Kaspersky was disabled and Process Hacker/related drivers interfered with protective processes, creating a defensive gap before encryption.

Stage 5

Mass encryption & extortion

24/09, 01:15 – 06:00. The attacker reviewed HIS/PACS data and archives, encrypted multiple files with the extension .piz, left ransom notes in the form !!!_README.txt and rebooted into normal mode at approximately 06:00.

A gap to note: the infographic describes scanning through 16/09 and intrusion on 23/09. Public data does not establish events on 17–22/09. Investigations should prioritize firewall, SQL Audit, Windows Security, RDP, Sysmon, EDR and configuration history for that interval.
No.Ransomware.VN illustration: Internet brute force against RDP, MSSQL and SMB
Additional No.Ransomware.VN illustration: Internet-exposed RDP/MSSQL/SMB and prolonged brute force before encryption.

MSSQL underpins many ERP, HIS, accounting and business systems. The concern is deployment: Internet-exposed management ports, weak passwords, excessive privileges, OS-command execution features or highly privileged extensions.

2.1. SQL account brute force sa

MITRE ATT&CK classifies password guessing as T1110.001. MSSQL/1433 and RDP/3389 are common password-guessing targets. Tens of thousands of Internet login failures without rate limits, IP reputation, firewall allowlists or SOC alerts give attackers time to test credentials.

2.2. CLR Assembly and execution beyond the database

No.Ransomware.VN illustration: SQL CLR Assembly and xp_cmdshell
Additional No.Ransomware.VN illustration: powerful SQL Server features such as CLR Assembly and xp_cmdshell require permission controls, audit and hardening.

SQL Server's legitimate CLR Integration runs .NET code in the Database Engine. Abused with high privileges, CLR assemblies can enable execution and persistence. MITRE describes SQL stored-procedure/CLR assembly abuse under T1505.001 – SQL Stored Procedures.

Microsoft also warns that assemblies with EXTERNAL_ACCESS or UNSAFE permissions can access resources outside the database. Production requires control of signing, trusted assemblies, assembly creation privileges and CLR configuration.

2.3. xp_cmdshell must not be a permanent switch

Microsoft states that xp_cmdshell is disabled by default on new installations and should generally stay disabled unless needed. Where legacy software requires it, limit enablement duration, invocation rights and monitor configuration changes.

Important: “Disabling xp_cmdshell” is necessary but insufficient. Excessively privileged database accounts may allow other routes through SQL Agent Jobs, CLR assemblies or extensions. Defense must follow least privilege + hardening + monitoring, not just disable one feature.
No.Ransomware.VN illustration: AnyDesk abused for remote access
Additional No.Ransomware.VN illustration: legitimate remote tools can become persistent access channels when installed outside approved administration.

AnyDesk is legitimate remote-desktop software. After intrusion, a common remote tool installed as a Service can provide durable, convenient access. MITRE ATT&CK describes this behavior under T1219.002 – Remote Desktop Software.

The defensive objective is not to ban AnyDesk at any cost, but to distinguish enterprise-approved remote tools and remote tools appearing outside procedure. A database server unexpectedly installing an AnyDesk service at midnight, connecting to unfamiliar infrastructure and then rebooting into Safe Mode is a high-priority sequence.

No.Ransomware.VN illustration: Safe Mode and disabling security software
Additional No.Ransomware.VN illustration: Safe Mode can be abused to weaken AV/EDR before ransomware impact.

Ransomware operators have used Safe Mode to reduce loaded security services/drivers. The old analysis (not independently verified) reports Kaspersky disabled and Process Hacker/related drivers interfering with protective processes. In ATT&CK, this is consistent with T1562.001 – Impair Defenses: Disable or Modify Tools.

A useful hunting rule: on critical servers, correlate Safe Mode boot changes, unusual services/drivers, AV/EDR stoppage, non-allowlisted RMM installation and Administrator logins from Internet IPs. Individual signals can be legitimate; a close sequence raises risk substantially.
No.Ransomware.VN illustration: encrypted data renamed with .piz
Additional No.Ransomware.VN illustration: .piz is an observed artifact in the case, not sufficient sole evidence for family attribution.

Files renamed to .piz establish one observed characteristic, but do not provide sufficient evidence to assign a ransomware family. Extensions are easily changed: operators may configure different values per victim, rebuild encryptors or reuse another group's suffix.

For more accurate identification, IR teams should collect at least:

  • Original ransom notes, filenames and content.
  • 1–3 pre/post-encryption files where comparison pairs exist.
  • Encrypted-file headers/trailers, markers and entropy.
  • Hashes of encryptors, loaders, DLLs/drivers and remote tools.
  • Process tree, command line, service, scheduled task, autorun.
  • IPs/domains/URLs related to RDP, AnyDesk or other C2 channels.
  • $MFT, $UsnJrnl, $LogFile, Windows Event Logs and SQL logs.

The table below is only behavior-level mapping of published observations, not attribution to an actor or family.

Observed behavior MITRE ATT&CK Defensive relevance
SQL account brute force sa T1110.001 – Password Guessing Alert on repeated login failures; lockouts/rate limits; IP restrictions; avoid direct exposure.
RDP login from an external IP T1021.001 – Remote Desktop Protocol VPN/ZTNA, access-layer MFA, allowlists and unusual-logon monitoring.
CLR Assembly / SQL execution path T1505.001 – SQL Stored Procedures Audit assemblies, stored procedures, SQL Agent Jobs and server configuration changes.
Installing AnyDesk as Service/Startup T1219.002 – Remote Desktop Software RMM allowlists, service-creation monitoring and remote-tool outbound sessions.
Disabling Kaspersky / interfering with protective processes T1562.001 – Disable or Modify Tools EDR tamper protection; alerts for stopped or modified security services/drivers.
Mass data encryption T1486 – Data Encrypted for Impact Detect rapid file rewrite/rename, use canary files and immutable/offline backups.

Build rules around behavior preceding ransomware rather than only hunting a ransomware file. High-value signals in this case include:

01 • MSSQL
A spike in login failures against sa; success after repeated failures; CLR/xp_cmdshell/OLE Automation changes; unfamiliar assemblies or SQL Agent Jobs.
02 • Windows
New services/drivers, unusual Scheduled Tasks/Startup entries and unexpected child processes from SQL or RMM services.
03 • Remote Access
Administrator RDP from unfamiliar ASNs/countries/IPs; AnyDesk/TeamViewer/RustDesk/ScreenConnect outside allowlists.
04 • Defense Evasion
Stopped AV/EDR services, boot configuration changes, Safe Mode reboots and tamper-protection failures.
05 • File Activity
Thousands of file renames/rewrites in minutes, increased entropy, unfamiliar extensions and ransom notes.
06 • Backup
Backup repositories mounted into production, mass deletion, retention changes and backup credentials used by compromised servers.

8.1. Do not expose RDP/MSSQL directly to the Internet

This is the first priority. CISA recommends restricting or removing direct RDP. Where remote access is needed, use VPN/ZTNA, access-layer MFA, IP restrictions, session logging and separate administrator/user accounts.

8.2. Apply least privilege to SQL accounts

Business applications should not use sa or logins with sysadmin unless genuinely required. Use separate application logins with access only to required databases; prohibit assembly/SQL Agent Job creation and server changes where business functions do not require them.

8.3. Place MFA at the right layer

MFA is strategically sound but must be implemented at the appropriate layer. Traditional SQL Authentication cannot simply enable MFA for account saas Microsoft 365 can. Prioritize MFA on VPN/ZTNA, AD/Entra accounts, RDP gateways, PAM and management portals. Restrict SQL authentication and use Windows/AD authentication where appropriate.

8.4. Separate backups from production's blast radius

CISA emphasizes offline/immutable backups and regular restore tests. NAS/share/object-storage backups continually mounted with production credentials that can delete/write may be encrypted or destroyed alongside primary data.

8.5. Monitor critical configuration changes

On database servers, changes to CLR, xp_cmdshell, OLE Automation, SQL Agent, sysadmin privileges, startup procedures and service accounts require an audit trail. Send alerts to an independent system so deleting host logs cannot erase every artifact.

A point requiring care: the original caption recommends OS/database patches, a necessary measure. Public case data does not establish missing patches as the direct cause. Stronger evidence points to Internet exposure, brute force/credentials, SQL privileges and abuse of management features.
  1. Isolate the network immediately but avoid rushed deletion/reset operations that destroy artifacts.
  2. Disconnect external access: RDP, suspected VPN accounts, uncontrolled AnyDesk/RMM and unusual firewall rules.
  3. Preserve evidence: Event Logs, SQL Logs/Audit, Sysmon/EDR telemetry, $MFT, $UsnJrnl, useful RAM contents and encryptor/driver/ransom-note samples.
  4. Do not immediately restore over the infected system. Build a clean recovery environment and identify persistence first.
  5. Check backups in order of trust: immutable/offline → independent snapshots → copies with separate credentials → supplementary data sources.
  6. Identify ransomware using multiple artifacts, not just an extension.
  7. Prioritize critical business data such as SQL MDF/LDF, HIS/PACS and ERP before lower-priority files.

The chain described in the old No.Ransomware.VN version (not independently verified) illustrates a principle: ransomware is often the final stage, not the first stage of an incident. Focusing only on an encryptor and the extension .pizcan miss valuable artifacts: prolonged brute force, abused SQL privileges, CLR assemblies, legitimate remote tools used as C2, Safe Mode and disabled defenses.

For organizations with SQL Server, ERP/HIS/PACS or critical internal systems, reducing Internet exposure, separating privileges, hardening SQL, controlling RMM, monitoring changes and maintaining immutable/offline backups are more valuable than expecting one antivirus product to stop the entire chain.

No.Ransomware.VN's message: do not wait for renamed files to recognize a ransomware incident. Treat brute force, unfamiliar remote tools, SQL privilege changes and disabled security services as pieces of one picture, and investigate the timeline.
  1. CyRadar – the post “RANSOMWARE ATTACK: LESSONS FROM A REAL INCIDENT” and the infographic supplied with the original content. Main page: https://cyradar.com/
  2. CyRadar — “MSSQL server attack campaign: three backdoor layers and fileless malware persisting for over six weeks”: cyradar.com/2026/09/08/...
  3. Microsoft Learn – Create an Assembly / SQL CLR Security: learn.microsoft.com/.../creating-an-assembly
  4. Microsoft Learn – xp_cmdshell server configuration: learn.microsoft.com/.../xp-cmdshell-server-configuration-option
  5. MITRE ATT&CK – T1110.001 Password Guessing: attack.mitre.org/techniques/T1110/001/
  6. MITRE ATT&CK – T1021.001 Remote Desktop Protocol: attack.mitre.org/techniques/T1021/001/
  7. MITRE ATT&CK – T1505.001 SQL Stored Procedures: attack.mitre.org/techniques/T1505/001/
  8. MITRE ATT&CK – T1219.002 Remote Desktop Software: attack.mitre.org/techniques/T1219/002/
  9. MITRE ATT&CK – T1486 Data Encrypted for Impact: attack.mitre.org/techniques/T1486/
  10. CISA – #StopRansomware Guide: cisa.gov/stopransomware/ransomware-guide
SQLForensicTTPIncident Response
CyRadar — MSSQL campaign, three backdoor layers and fileless malware08/09/2026 · Reviewed primary source. It does not confirm the .PIZ, AnyDesk or Safe Mode chain attributed to it in the old No.Ransomware.VN article.
MITRE ATT&CK — Enterprise TacticsA behavioral reference framework; attacks do not necessarily follow one sequence.
MITRE ATT&CK — T1486: Data Encrypted for ImpactReference for encryption of data to cause disruption.
CISA — #StopRansomware GuideGuidance on prevention, response and recovery.

Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.

· Correction: withdrew attribution of .PIZ / AnyDesk / Safe Mode and approximately 38,000 brute-force attempts to the linked CyRadar report. Retained the archive for comparison, labeled it Unconfirmed and added the primary source's actual scope.

· Pre-consolidation No.Ransomware.VN version; original title and timestamp retained in the source record.

Corrections policy
N
No.Ransomware.VN

TUNGTEK's ransomware awareness and prevention initiative. Original content is preserved and edited within Ransomware.VN.