Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users.
The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code collection, and preparation to access additional systems.
The investigation did not establish how the attackers first entered the environment or identify a named malware family. The available records describe a toolkit rather than a single implant. ThreatMon researchers identified the exposed infrastructure during routine threat hunting.
ThreatMon said in a report shared with Cyber Security News (CSN) that the server contained 17 named tools, offering an unusually detailed view of the operation after the initial compromise.
The findings reveal a second exposure layered onto the original intrusion, but not a confirmed passenger data breach. Researchers found no evidence proving successful access to additional systems or the theft of sensitive passenger, payment, or equivalent business data.
Hackers Turned a Microsoft SQL Server Into a Command Channel
The attackers used xp_cmdshell, a SQL Server feature that can run operating system commands when enabled. Recovered tools submitted Windows commands and encoded PowerShell through database sessions, allowing SQL access to become a working channel into the underlying Windows system.
This mechanism resembles earlier cases involving attacks on SQL servers, where database access enabled commands outside the database itself.
Here, however, the recovered evidence describes activity after compromise rather than proving a particular vulnerability, password attack, or other initial entry method.
The same database connection could also carry files outward. Recovered tooling read file contents, divided them into smaller pieces, converted those pieces into Base64 text, and returned them through SQL query output instead of opening a separate communication channel.
Base64 is a way to represent data as text, not encryption. In this workflow, it made file contents transferable through database responses. A connection used to submit commands could therefore also return collected information without requiring a conventional malware control server.
The danger of database command execution has also appeared in Mjobtime application exploitation cases, although ThreatMon did not connect this intrusion to that software. The relevant similarity is the use of database functionality to reach the operating system and execute commands.
HTTP records showed a payload retrieval by the victim environment at 16:20 on September 25. An unrelated host explored the exposed server between 16:21 and 16:23, followed by additional hosts retrieving tools and collected artifacts between 18:04 and 18:05.
Credential Exposure
The exposed toolkit included scripts for collecting browser and Windows credentials, testing SQL logins, and transferring files.
Mimikatz artifacts showed credential dumping activity, a technique also seen in HiddenGh0st credential theft campaigns, although no link between the operations was established.
Researchers also recovered SQL Server Management Studio connection history, database usernames, and saved password material protected by Windows DPAPI.
These records could help attackers identify additional targets, but their presence does not mean that every saved password was successfully decrypted.
Collected source code and configuration files referenced database connections, OAuth, email, SFTP, and payment or reporting integrations.
ThreatMon withheld sensitive values, victim hostnames, usernames, and other private material from its public release rather than exposing potentially reusable secrets.
Recovered utilities tested credential combinations against other SQL systems and checked access to SMB administrative shares.
The evidence supports attempts to reuse credentials and preparation to move across the network, not confirmation that attackers successfully compromised those additional systems.
Defenders should review historical network connections against the published indicators and search endpoints for matching hashes and the reported working directory.
Unexpected xp_cmdshell use, encoded PowerShell, or unusual file operations under a SQL Server service account warrants immediate investigation.
Saved database connections and password records should also be treated as sensitive information. ThreatMon warned that credentials or secrets reaching the exposed staging server must be considered compromised, because unrelated parties accessed material and the original attacker was not necessarily its only recipient.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IPv4 address | 151.243.232.123 | Exposed attacker staging and stolen-material server. |
| SHA256 | c38f49ba68b891bb476510704cddf080798f3c70075e2a517e98e04e833f64fa | Published hash for exfil.py. |
| SHA256 | 33aeaaa3d57b7785ef2be5b8ccd39d534b8af50e0cd32a5036fdb64601a52fc9 | Published hash for upload.py. |
| SHA256 | 8b6c53e3d57b4c3049f3d0765a44d9a52feb6af78f1eaa5aff19daf1b9665998 | Published hash for sqlspray.ps1. |
| Windows path | C:WindowsTempartex | Working directory identified for endpoint searches. |
| File name | chrome_dump.ps1 | Script for extracting browser credentials. |
| File name | cred_dump.ps1 | Script for extracting Windows credentials. |
| File name | cred_enum.ps1 | Script for enumerating available credentials. |
| File name | sqlspray.ps1 | Utility for testing SQL credentials against target systems. |
| File name | mssqltest.ps1 | Utility for testing SQL credentials against target systems. |
| File name | exfil.py | Recovered file-transfer tool. |
| File name | upload.py | Recovered file-transfer tool. |
| File name | vault.cmd | Tool likely associated with Windows Credential Manager or Vault access. |
| File name | vtest.ps1 | Tool likely associated with Windows Credential Manager or Vault access. |
| Directory | loot/ | Exposed directory containing collected material. |
| Directory | loot2/ | Additional exposed directory containing collected material. |
| File name | cred_dec.txt | Artifact recovered from the exposed server. |
| File name | mdump.txt | Artifact recovered from the exposed server. |
| File name | httpd.log | HTTP log artifact recovered from the exposed server. |
| Execution artifact | cmd.exe | Legitimate Windows command interpreter; suspicious execution under a SQL Server service account requires investigation. |
| Execution artifact | powershell.exe | Legitimate PowerShell executable; suspicious execution through xp_cmdshell requires investigation. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

