New Hacker Group ‘GambleForce’ Tageting APAC Firms Using SQL Injection Attacks

Share:

A previously unknown hacker outfit called GambleForce has been attributed to a series of SQL injection attacks against companies primarily in the Asia-Pacific (APAC) region since at least September 2023.

“GambleForce uses a set of basic yet very effective techniques, including SQL injections and the exploitation of vulnerable website content management systems (CMS) to steal sensitive information, such as user credentials,” Singapore-headquartered Group-IB said in a report shared with The Hacker News.

The group is estimated to have targeted 24 organizations in the gambling, government, retail, and travel sectors across Australia, Brazil, China, India, Indonesia, the Philippines, South Korea, and Thailand. Six of these attacks were successful.

The modus operandi of GambleForce is its exclusive reliance on open-source tools like dirsearch, sqlmap, tinyproxy, and redis-rogue-getshell at different stages of the attacks with the ultimate goal of exfiltrating sensitive information from compromised networks.

Also used by the threat actor is the legitimate post-exploitation framework known as Cobalt Strike. Interestingly, the version of the tool discovered on its attack infrastructure used commands in Chinese, although the group’s origins are far from clear.

GambleForce

The attack chains entail the abuse of victims’ public-facing applications of victims by exploiting SQL injections as well as the exploitation of CVE-2023-23752, a medium-severity flaw in Joomla CMS, to gain unauthorized access to a Brazilian company.

The SQL injections are accomplished by means of sqlmap, a popular open-source pentesting tool that’s designed to automate the process of identifying database servers vulnerable to SQL injections and weaponizing them to take over the systems.

In such attacks, the threat actors inject malicious SQL code into a public facing web page of the targeted website, allowing them to get around default authentication protections and access sensitive data, such as hashed and plaintext user credentials.

It’s currently not known how GambleForce leverages the stolen information. The cybersecurity firm said it also took down the adversary’s command-and-control (C2) server and notified the identified victims.

“Web injections are among the oldest and most popular attack vectors,” Nikita Rostovcev, senior threat analyst at Group-IB, said.

“And the reason being is that sometimes developers overlook the importance of input security and data validation. Insecure coding practices, incorrect database settings, and outdated software create a fertile environment for SQL injection attacks on web applications.”

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:14 am, Jun 21, 2025
weather icon 16°C
L: 14° | H: 17°
clear sky
Humidity: 82 %
Pressure: 1019 mb
Wind: 7 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 1%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
14° | 17°°C 0.2 mm 20% 10 mph 75 % 1019 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 26°°C 0.34 mm 34% 15 mph 77 % 1013 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 23°°C 0 mm 0% 14 mph 75 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
15° | 25°°C 0.2 mm 20% 14 mph 72 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
17° | 21°°C 1 mm 100% 10 mph 85 % 1011 mb 0 mm/h
Today 7:00 am
weather icon
17° | 18°°C 0 mm 0% 6 mph 75 % 1019 mb 0 mm/h
Today 10:00 am
weather icon
23° | 26°°C 0 mm 0% 8 mph 56 % 1018 mb 0 mm/h
Today 1:00 pm
weather icon
31° | 31°°C 0 mm 0% 9 mph 25 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
32° | 32°°C 0 mm 0% 10 mph 23 % 1016 mb 0 mm/h
Today 7:00 pm
weather icon
26° | 26°°C 0 mm 0% 9 mph 27 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
25° | 25°°C 0.2 mm 20% 5 mph 39 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0.34 mm 34% 7 mph 66 % 1013 mb 0 mm/h
Tomorrow 4:00 am
weather icon
19° | 19°°C 0.25 mm 25% 10 mph 77 % 1012 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,823.46
-1.02%
Ethereum(ETH)
€2,104.99
-3.59%
Tether(USDT)
€0.87
0.00%
XRP(XRP)
€1.85
-1.22%
Solana(SOL)
€122.15
-3.21%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.141743
-3.33%
Shiba Inu(SHIB)
€0.000010
-1.13%
Pepe(PEPE)
€0.000009
-1.04%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top