Critical Microsoft SQL Server Vulnerability Lets Attackers Exfiltrate Data
Key Takeaways Attackers leveraged a Microsoft SQL Server to execute commands and exfiltrate data in an intrusion linked to a Viva Aerobus environment. The compromised SQL Server was used as a command...
Key Takeaways
- Attackers leveraged a Microsoft SQL Server to execute commands and exfiltrate data in an intrusion linked to a Viva Aerobus environment.
- The compromised SQL Server was used as a command and control channel via the
xp_cmdshellfeature. - A publicly accessible attacker-controlled server inadvertently exposed a toolkit containing 17 distinct attack tools and various stolen artifacts.
- The intrusion involved credential harvesting, source code collection, and reconnaissance for further lateral movement within the network.
- While significant activity was observed, researchers found no conclusive evidence of a successful breach of sensitive passenger or payment data, or compromise of additional systems.
Cybersecurity researchers have uncovered a sophisticated intrusion involving a Microsoft SQL Server, which was weaponized by attackers to execute commands and siphon off data from a network associated with Viva Aerobus. The incident came to light after the attackers’ own staging server was left publicly exposed, revealing a comprehensive toolkit and collected data to unrelated internet users.
Table Of Content
The malicious activity, spanning from September 25 to 29, 2026, focused on gathering credentials, collecting source code, and establishing groundwork for potential access to other systems. While the initial point of entry remains undetermined, and no specific malware family was identified, the investigation revealed a robust set of attack tools rather than a singular piece of malware.
ThreatMon researchers, during their routine threat intelligence gathering, discovered the exposed infrastructure. In a report shared with Cyber Security News (CSN), ThreatMon detailed that the server contained 17 distinct tools. This unusual exposure provided a rare, in-depth look into the post-compromise operations of the attackers. The findings highlight a critical secondary exposure, though no definitive evidence confirmed a breach of passenger data or the successful compromise of additional sensitive systems, including passenger, payment, or other proprietary business information.
Hackers Turned a Microsoft SQL Server Into a Command Channel
The attackers exploited the xp_cmdshell feature within Microsoft SQL Server, which, when enabled, allows the execution of operating system commands. The recovered tools demonstrated how Windows commands and encoded PowerShell scripts were submitted through database sessions, effectively transforming SQL access into a backdoor to the underlying Windows operating system. This method is reminiscent of previous SQL server attacks where database privileges were escalated to execute commands outside the database environment.
However, in this specific case, the unearthed evidence primarily details the post-compromise activities rather than pinpointing the initial vulnerability, password attack, or other entry vectors. The same database connection facilitating command execution was also ingeniously used for data exfiltration. The attackers’ tools were designed to read file contents, segment them, encode these segments into Base64 text, and then transmit them through SQL query outputs. This technique eliminated the need for a separate command-and-control channel, allowing the same connection to be used for both issuing commands and receiving stolen data.
It’s important to note that Base64 encoding is a method for representing binary data as text and does not provide encryption. This approach enabled the transfer of file contents via standard database responses. The versatility of this method allowed the attackers to operate stealthily, using the established SQL connection for both instructing the compromised server and extracting information, bypassing the need for conventional malware command-and-control infrastructure. The inherent risk of database command execution has been observed in other incidents, such as Mjobtime application exploitation cases, though ThreatMon did not establish a direct link between this intrusion and that specific software. The commonality lies in the abuse of database functionalities to gain operating system-level command execution.
Analysis of HTTP logs revealed that the victim environment retrieved a payload at 16:20 on September 25. Subsequently, an unrelated host was observed exploring the exposed attacker server between 16:21 and 16:23, with additional hosts retrieving tools and collected artifacts between 18:04 and 18:05, indicating potential further dissemination of the compromised data or tools.
Credential Exposure
The publicly exposed toolkit contained various scripts designed for credential harvesting, including those for collecting browser and Windows credentials, testing SQL logins, and facilitating file transfers. Notably, Mimikatz artifacts were discovered, signaling credential dumping activities—a tactic also observed in HiddenGh0st campaigns, though no direct connection between these operations was established.
Further examination revealed SQL Server Management Studio connection histories, database usernames, and password material protected by Windows DPAPI. While these records could assist attackers in identifying additional targets, their mere presence does not confirm the successful decryption of all saved passwords. The collected source code and configuration files contained references to various critical integrations, including database connections, OAuth, email, SFTP, and payment or reporting systems. ThreatMon responsibly redacted sensitive values, victim hostnames, usernames, and other private information from their public release to prevent the reuse of potentially compromised secrets.
The recovered utilities also showed attempts to test credential combinations against other SQL systems and check access to SMB administrative shares. This suggests the attackers were actively attempting to reuse credentials and prepare for lateral movement within the network. However, this evidence does not confirm successful compromise of these additional systems. ThreatMon emphasized that any credentials or secrets found on the exposed staging server must be considered compromised, given that multiple, unrelated parties accessed the material, indicating the original attacker was likely not the sole recipient.
Indicators of Compromise (IoCs):-



No Comment! Be the first one.