CyberSecurityNews

Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel


Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users.

The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code collection, and preparation to access additional systems.

The investigation did not establish how the attackers first entered the environment or identify a named malware family. The available records describe a toolkit rather than a single implant. ThreatMon researchers identified the exposed infrastructure during routine threat hunting.

ThreatMon said in a report shared with Cyber Security News (CSN) that the server contained 17 named tools, offering an unusually detailed view of the operation after the initial compromise.

The findings reveal a second exposure layered onto the original intrusion, but not a confirmed passenger data breach. Researchers found no evidence proving successful access to additional systems or the theft of sensitive passenger, payment, or equivalent business data.

Hackers Turned a Microsoft SQL Server Into a Command Channel

The attackers used xp_cmdshell, a SQL Server feature that can run operating system commands when enabled. Recovered tools submitted Windows commands and encoded PowerShell through database sessions, allowing SQL access to become a working channel into the underlying Windows system.

This mechanism resembles earlier cases involving attacks on SQL servers, where database access enabled commands outside the database itself.

Here, however, the recovered evidence describes activity after compromise rather than proving a particular vulnerability, password attack, or other initial entry method.

The same database connection could also carry files outward. Recovered tooling read file contents, divided them into smaller pieces, converted those pieces into Base64 text, and returned them through SQL query output instead of opening a separate communication channel.

Base64 is a way to represent data as text, not encryption. In this workflow, it made file contents transferable through database responses. A connection used to submit commands could therefore also return collected information without requiring a conventional malware control server.

The danger of database command execution has also appeared in Mjobtime application exploitation cases, although ThreatMon did not connect this intrusion to that software. The relevant similarity is the use of database functionality to reach the operating system and execute commands.

HTTP records showed a payload retrieval by the victim environment at 16:20 on September 25. An unrelated host explored the exposed server between 16:21 and 16:23, followed by additional hosts retrieving tools and collected artifacts between 18:04 and 18:05.

Credential Exposure

The exposed toolkit included scripts for collecting browser and Windows credentials, testing SQL logins, and transferring files.

Mimikatz artifacts showed credential dumping activity, a technique also seen in HiddenGh0st credential theft campaigns, although no link between the operations was established.

Researchers also recovered SQL Server Management Studio connection history, database usernames, and saved password material protected by Windows DPAPI.

These records could help attackers identify additional targets, but their presence does not mean that every saved password was successfully decrypted.

Collected source code and configuration files referenced database connections, OAuth, email, SFTP, and payment or reporting integrations.

ThreatMon withheld sensitive values, victim hostnames, usernames, and other private material from its public release rather than exposing potentially reusable secrets.

Recovered utilities tested credential combinations against other SQL systems and checked access to SMB administrative shares.

The evidence supports attempts to reuse credentials and preparation to move across the network, not confirmation that attackers successfully compromised those additional systems.

Defenders should review historical network connections against the published indicators and search endpoints for matching hashes and the reported working directory.

Unexpected xp_cmdshell use, encoded PowerShell, or unusual file operations under a SQL Server service account warrants immediate investigation.

Saved database connections and password records should also be treated as sensitive information. ThreatMon warned that credentials or secrets reaching the exposed staging server must be considered compromised, because unrelated parties accessed material and the original attacker was not necessarily its only recipient.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IPv4 address151.243.232.123Exposed attacker staging and stolen-material server.
SHA256c38f49ba68b891bb476510704cddf080798f3c70075e2a517e98e04e833f64faPublished hash for exfil.py.
SHA25633aeaaa3d57b7785ef2be5b8ccd39d534b8af50e0cd32a5036fdb64601a52fc9Published hash for upload.py.
SHA2568b6c53e3d57b4c3049f3d0765a44d9a52feb6af78f1eaa5aff19daf1b9665998Published hash for sqlspray.ps1.
Windows pathC:WindowsTempartexWorking directory identified for endpoint searches.
File namechrome_dump.ps1Script for extracting browser credentials.
File namecred_dump.ps1Script for extracting Windows credentials.
File namecred_enum.ps1Script for enumerating available credentials.
File namesqlspray.ps1Utility for testing SQL credentials against target systems.
File namemssqltest.ps1Utility for testing SQL credentials against target systems.
File nameexfil.pyRecovered file-transfer tool.
File nameupload.pyRecovered file-transfer tool.
File namevault.cmdTool likely associated with Windows Credential Manager or Vault access.
File namevtest.ps1Tool likely associated with Windows Credential Manager or Vault access.
Directoryloot/Exposed directory containing collected material.
Directoryloot2/Additional exposed directory containing collected material.
File namecred_dec.txtArtifact recovered from the exposed server.
File namemdump.txtArtifact recovered from the exposed server.
File namehttpd.logHTTP log artifact recovered from the exposed server.
Execution artifactcmd.exeLegitimate Windows command interpreter; suspicious execution under a SQL Server service account requires investigation.
Execution artifactpowershell.exeLegitimate PowerShell executable; suspicious execution through xp_cmdshell requires investigation.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link