Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion
ThreatMon exposed an unauthenticated attacker staging server revealing MSSQL intrusion tooling and stolen data linked to a Viva Aerobus environment.
On September 25, 2026, a victim-side Microsoft SQL Server downloaded a payload from attacker host 151.243.232.123, which ThreatMon found left unauthenticated and hosting 17 post-exploitation tools plus loot directories. Attackers abused xp_cmdshell to run cmd.exe and Base64-encoded PowerShell under the SQL Server service account, harvesting credentials with tools like chrome_dump.ps1, cred_dump.ps1, and Mimikatz, and collecting SSMS artifacts to map internal databases. ThreatMon assessed the activity as credential harvesting and lateral-movement preparation, with no confirmed exfiltration of passenger or payment data; unrelated external hosts also accessed the exposed loot within minutes.