Larva-26002 Deploys ICE Cloud Client Scanner

Larva-26002 is actively deploying a Go-based scanner called ICE Cloud Client to target internet-exposed Microsoft SQL (MS-SQL) servers in 2026, according to AhnLab. The campaign abuses the BCP utility to export malicious payloads, reuses credentials like "ecomm/ecomm," and shifts from direct ransomware to scanner-driven propagation. Organizations should harden MS-SQL access, monitor BCP usage, and rotate credentials immediately.
Scoring Rationale
High actionability and vendor-backed evidence drive score, limited novelty as campaign reuses previous techniques continuously.
Practice interview problems based on real data
1,500+ SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


