Open staging server tied to Viva Aerobus SQL intrusion
ThreatMon found an open attacker server linked to a Viva Aerobus SQL intrusion, with credential tools and no confirmed passenger-data theft.
ThreatMon reported an intrusion tied to a Viva Aerobus environment in which a Microsoft SQL Server downloaded a payload on September 25, 2026, from attacker host 151.243.232.123. One account limits the finding to that date, while the other places activity from September 25 through 29. Attackers abused xp_cmdshell to run cmd.exe and Base64-encoded PowerShell under the SQL Server service account, collected browser, Windows Credential Manager, DPAPI, and SSMS credentials with scripts and Mimikatz, and returned chunked Base64-encoded files through SQL query results. The staging server was left unauthenticated with 17 post-exploitation tools and loot directories; unrelated hosts accessed the exposed material within minutes, and ThreatMon published SHA-256 indicators for exfil.py, upload.py, and sqlspray.ps1. Both sources say passenger and payment-data theft and further-system access were not confirmed, though material that reached the public server should be treated as compromised.
- A Viva Aerobus-linked Microsoft SQL Server downloaded a payload on September 25, 2026, from attacker host 151.243.232.123; one source dates activity through September 29.
- ThreatMon found that host unauthenticated, holding 17 post-exploitation tools and loot directories.
- Attackers used xp_cmdshell to run cmd.exe and Base64-encoded PowerShell under the SQL Server service account.
- Credential collection targeted browsers, Windows Credential Manager, DPAPI, and SSMS saved connections, using chrome_dump.ps1, cred_dump.ps1, and Mimikatz.
- Files were split, Base64-encoded, and returned through SQL query results; recovered activity also included SQL login testing and file transfer.
- Both sources report no confirmed passenger or payment-data theft and no confirmed access to further systems.
- Unrelated external hosts reached the exposed loot within minutes, and secrets on 151.243.232.123 should be treated as compromised.
- ThreatMon published SHA-256 indicators for exfil.py, upload.py, and sqlspray.ps1.
Coverage timelineoldest first · each row is one article
- · 11h agoExposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion
GBHackers· 60
ThreatMon exposed an unauthenticated attacker staging server revealing MSSQL intrusion tooling and stolen data linked to a Viva Aerobus environment.
- · 9h agoHackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
Cyber Security News· 62
Attackers abused a Viva Aerobus SQL Server to run commands and steal files, then exposed tools and data online.