Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
Attackers abused a Viva Aerobus SQL Server to run commands and steal files, then exposed tools and data online.
ThreatMon reported an intrusion tied to a Viva Aerobus environment between September 25 and 29, 2026. Attackers used Microsoft SQL Server xp_cmdshell and encoded PowerShell to run Windows commands and return chunked, Base64-encoded files through SQL query results. Recovered scripts and Mimikatz artifacts indicate browser and Windows credential theft, SQL login testing, and file transfer. Researchers found no proof of passenger or payment-data theft or successful access to further systems, but said secrets that reached the publicly exposed staging server 151.243.232.123 should be treated as compromised.
- Activity ran September 25–29, 2026, in a Viva Aerobus-linked environment.
- xp_cmdshell and encoded PowerShell turned SQL access into OS commands.
- Files were split, Base64-encoded, and returned in SQL query output.
- Public server 151.243.232.123 exposed tools and stolen material.
- No confirmed passenger, payment, or further-system compromise.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 151.243.232.123 | compromise (IoCs):- Type Indicator Description IPv4 address 151.243.232.123 Exposed attacker staging and stolen-material server. SHA256 |
| sha256 | 33aeaaa3d57b7785ef2be5b8ccd39d534b8af50e0cd32a5036fdb64601a52fc9 | 5e2a517e98e04e833f64fa Published hash for exfil.py . SHA256 33aeaaa3d57b7785ef2be5b8ccd39d534b8af50e0cd32a5036fdb64601a52fc9 Published hash for upload.py . SHA256 8b6c53e3d57b4c3049f3d |
| sha256 | 8b6c53e3d57b4c3049f3d0765a44d9a52feb6af78f1eaa5aff19daf1b9665998 | 32a5036fdb64601a52fc9 Published hash for upload.py . SHA256 8b6c53e3d57b4c3049f3d0765a44d9a52feb6af78f1eaa5aff19daf1b9665998 Published hash for sqlspray.ps1 . Windows path C:\Windows\T |
| sha256 | c38f49ba68b891bb476510704cddf080798f3c70075e2a517e98e04e833f64fa | Exposed attacker staging and stolen-material server. SHA256 c38f49ba68b891bb476510704cddf080798f3c70075e2a517e98e04e833f64fa Published hash for exfil.py . SHA256 33aeaaa3d57b7785ef2be5 |
Full article963 words · extracted from cybersecuritynews.com · click to collapse
Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users.
The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code collection, and preparation to access additional systems.
The investigation did not establish how the attackers first entered the environment or identify a named malware family. The available records describe a toolkit rather than a single implant. ThreatMon researchers identified the exposed infrastructure during routine threat hunting.
ThreatMon said in a report shared with Cyber Security News (CSN) that the server contained 17 named tools, offering an unusually detailed view of the operation after the initial compromise.
The findings reveal a second exposure layered onto the original intrusion, but not a confirmed passenger data breach. Researchers found no evidence proving successful access to additional systems or the theft of sensitive passenger, payment, or equivalent business data.
Hackers Turned a Microsoft SQL Server Into a Command Channel
The attackers used xp_cmdshell, a SQL Server feature that can run operating system commands when enabled. Recovered tools submitted Windows commands and encoded PowerShell through database sessions, allowing SQL access to become a working channel into the underlying Windows system.
This mechanism resembles earlier cases involving attacks on SQL servers, where database access enabled commands outside the database itself.
Here, however, the recovered evidence describes activity after compromise rather than proving a particular vulnerability, password attack, or other initial entry method.
The same database connection could also carry files outward. Recovered tooling read file contents, divided them into smaller pieces, converted those pieces into Base64 text, and returned them through SQL query output instead of opening a separate communication channel.
Base64 is a way to represent data as text, not encryption. In this workflow, it made file contents transferable through database responses. A connection used to submit commands could therefore also return collected information without requiring a conventional malware control server.
The danger of database command execution has also appeared in Mjobtime application exploitation cases, although ThreatMon did not connect this intrusion to that software. The relevant similarity is the use of database functionality to reach the operating system and execute commands.
HTTP records showed a payload retrieval by the victim environment at 16:20 on September 25. An unrelated host explored the exposed server between 16:21 and 16:23, followed by additional hosts retrieving tools and collected artifacts between 18:04 and 18:05.
Credential Exposure
The exposed toolkit included scripts for collecting browser and Windows credentials, testing SQL logins, and transferring files.
Mimikatz artifacts showed credential dumping activity, a technique also seen in HiddenGh0st credential theft campaigns, although no link between the operations was established.
Researchers also recovered SQL Server Management Studio connection history, database usernames, and saved password material protected by Windows DPAPI.
These records could help attackers identify additional targets, but their presence does not mean that every saved password was successfully decrypted.
Collected source code and configuration files referenced database connections, OAuth, email, SFTP, and payment or reporting integrations.
ThreatMon withheld sensitive values, victim hostnames, usernames, and other private material from its public release rather than exposing potentially reusable secrets.
Recovered utilities tested credential combinations against other SQL systems and checked access to SMB administrative shares.
The evidence supports attempts to reuse credentials and preparation to move across the network, not confirmation that attackers successfully compromised those additional systems.
Defenders should review historical network connections against the published indicators and search endpoints for matching hashes and the reported working directory.
Unexpected xp_cmdshell use, encoded PowerShell, or unusual file operations under a SQL Server service account warrants immediate investigation.
Saved database connections and password records should also be treated as sensitive information. ThreatMon warned that credentials or secrets reaching the exposed staging server must be considered compromised, because unrelated parties accessed material and the original attacker was not necessarily its only recipient.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.