Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft SQL Server Vulnerability Lets Attackers Exfiltrate Data
October 2, 2026
Critical Flaws in JetBrains TeamCity Let Attackers Steal Credentials
October 2, 2026
Critical cPanel & WHM Flaws Let Attackers Run Commands
October 2, 2026
Home/Threats/Critical Microsoft SQL Server Vulnerability Lets Attackers Exfiltrate Data
Threats

Critical Microsoft SQL Server Vulnerability Lets Attackers Exfiltrate Data

Key Takeaways Attackers leveraged a Microsoft SQL Server to execute commands and exfiltrate data in an intrusion linked to a Viva Aerobus environment. The compromised SQL Server was used as a command...

David kimber
David kimber
October 2, 2026 4 Min Read
2 0

Key Takeaways

  • Attackers leveraged a Microsoft SQL Server to execute commands and exfiltrate data in an intrusion linked to a Viva Aerobus environment.
  • The compromised SQL Server was used as a command and control channel via the xp_cmdshell feature.
  • A publicly accessible attacker-controlled server inadvertently exposed a toolkit containing 17 distinct attack tools and various stolen artifacts.
  • The intrusion involved credential harvesting, source code collection, and reconnaissance for further lateral movement within the network.
  • While significant activity was observed, researchers found no conclusive evidence of a successful breach of sensitive passenger or payment data, or compromise of additional systems.

Cybersecurity researchers have uncovered a sophisticated intrusion involving a Microsoft SQL Server, which was weaponized by attackers to execute commands and siphon off data from a network associated with Viva Aerobus. The incident came to light after the attackers’ own staging server was left publicly exposed, revealing a comprehensive toolkit and collected data to unrelated internet users.

Table Of Content

  • Key Takeaways
  • Hackers Turned a Microsoft SQL Server Into a Command Channel
  • Credential Exposure

The malicious activity, spanning from September 25 to 29, 2026, focused on gathering credentials, collecting source code, and establishing groundwork for potential access to other systems. While the initial point of entry remains undetermined, and no specific malware family was identified, the investigation revealed a robust set of attack tools rather than a singular piece of malware.

ThreatMon researchers, during their routine threat intelligence gathering, discovered the exposed infrastructure. In a report shared with Cyber Security News (CSN), ThreatMon detailed that the server contained 17 distinct tools. This unusual exposure provided a rare, in-depth look into the post-compromise operations of the attackers. The findings highlight a critical secondary exposure, though no definitive evidence confirmed a breach of passenger data or the successful compromise of additional sensitive systems, including passenger, payment, or other proprietary business information.

Hackers Turned a Microsoft SQL Server Into a Command Channel

The attackers exploited the xp_cmdshell feature within Microsoft SQL Server, which, when enabled, allows the execution of operating system commands. The recovered tools demonstrated how Windows commands and encoded PowerShell scripts were submitted through database sessions, effectively transforming SQL access into a backdoor to the underlying Windows operating system. This method is reminiscent of previous SQL server attacks where database privileges were escalated to execute commands outside the database environment.

However, in this specific case, the unearthed evidence primarily details the post-compromise activities rather than pinpointing the initial vulnerability, password attack, or other entry vectors. The same database connection facilitating command execution was also ingeniously used for data exfiltration. The attackers’ tools were designed to read file contents, segment them, encode these segments into Base64 text, and then transmit them through SQL query outputs. This technique eliminated the need for a separate command-and-control channel, allowing the same connection to be used for both issuing commands and receiving stolen data.

It’s important to note that Base64 encoding is a method for representing binary data as text and does not provide encryption. This approach enabled the transfer of file contents via standard database responses. The versatility of this method allowed the attackers to operate stealthily, using the established SQL connection for both instructing the compromised server and extracting information, bypassing the need for conventional malware command-and-control infrastructure. The inherent risk of database command execution has been observed in other incidents, such as Mjobtime application exploitation cases, though ThreatMon did not establish a direct link between this intrusion and that specific software. The commonality lies in the abuse of database functionalities to gain operating system-level command execution.

Analysis of HTTP logs revealed that the victim environment retrieved a payload at 16:20 on September 25. Subsequently, an unrelated host was observed exploring the exposed attacker server between 16:21 and 16:23, with additional hosts retrieving tools and collected artifacts between 18:04 and 18:05, indicating potential further dissemination of the compromised data or tools.

Credential Exposure

The publicly exposed toolkit contained various scripts designed for credential harvesting, including those for collecting browser and Windows credentials, testing SQL logins, and facilitating file transfers. Notably, Mimikatz artifacts were discovered, signaling credential dumping activities—a tactic also observed in HiddenGh0st campaigns, though no direct connection between these operations was established.

Further examination revealed SQL Server Management Studio connection histories, database usernames, and password material protected by Windows DPAPI. While these records could assist attackers in identifying additional targets, their mere presence does not confirm the successful decryption of all saved passwords. The collected source code and configuration files contained references to various critical integrations, including database connections, OAuth, email, SFTP, and payment or reporting systems. ThreatMon responsibly redacted sensitive values, victim hostnames, usernames, and other private information from their public release to prevent the reuse of potentially compromised secrets.

The recovered utilities also showed attempts to test credential combinations against other SQL systems and check access to SMB administrative shares. This suggests the attackers were actively attempting to reuse credentials and prepare for lateral movement within the network. However, this evidence does not confirm successful compromise of these additional systems. ThreatMon emphasized that any credentials or secrets found on the exposed staging server must be considered compromised, given that multiple, unrelated parties accessed the material, indicating the original attacker was likely not the sole recipient.

Indicators of Compromise (IoCs):-

Type Indicator Description
IPv4 address 151[.]243[.]232[.]123 Exposed attacker staging and stolen-material server.
SHA256 c38f49ba68b891bb476510704cddf080798f3c70075e2a517e98e04e833f64fa Published hash for exfil.py.
SHA256 33aeaaa3d57b7785ef2be5b8ccd39d534b8af50e0cd32a5036fdb64601a52fc9 Published hash for upload.py. <a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/dde97bd7-b33d-4525-

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerMalwareSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Flaws in JetBrains TeamCity Let Attackers Steal Credentials

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Exposed WordPress Backups Leak AWS and Email Credentials
October 2, 2026
Critical Zammad Flaws Let Attackers Gain Remote Code Execution
October 2, 2026
Sony PS5 Update Patches Relapse Jailbreak Vulnerabilities
October 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us