Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
Attackers abused a Viva Aerobus SQL Server to run commands and steal files, then exposed tools and data online.
ThreatMon reported an intrusion tied to a Viva Aerobus environment between September 25 and 29, 2026. Attackers used Microsoft SQL Server xp_cmdshell and encoded PowerShell to run Windows commands and return chunked, Base64-encoded files through SQL query results. Recovered scripts and Mimikatz artifacts indicate browser and Windows credential theft, SQL login testing, and file transfer. Researchers found no proof of passenger or payment-data theft or successful access to further systems, but said secrets that reached the publicly exposed staging server 151.243.232.123 should be treated as compromised.