Recent cyber activities have highlighted vulnerabilities in Microsoft SQL Servers, as hackers turned one into a tool for executing commands and extracting data. This intrusion, linked to a Viva Aerobus environment, involved the misuse of a publicly accessible server, inadvertently exposing attack tools to the internet.
Details of the Intrusion
The breach, occurring between September 25 and 29, 2026, involved gathering credentials, collecting source code, and setting up access to further systems. Despite intense investigations, the initial entry method remains unidentified, and no specific malware has been named. ThreatMon, a cybersecurity research firm, discovered the exposed infrastructure during its routine threat hunting activities.
The server contained 17 different tools, providing detailed insights into the attackers’ methods post-compromise. However, the findings did not confirm any breaches of sensitive passenger data or access to additional systems.
Exploitation of SQL Server Capabilities
Hackers exploited the xp_cmdshell feature of the SQL Server, which allows execution of operating system commands when enabled. They used Windows commands and encoded PowerShell to interact with the system through database sessions, turning SQL access into a channel for operating system-level operations.
This method mirrors previous attacks where SQL server access facilitated command execution beyond the database itself. However, the evidence in this case primarily documents activity following the compromise, rather than detailing the initial vulnerability exploited.
File exfiltration was achieved by reading, segmenting, and converting file contents into Base64 text, which was then transmitted via SQL query outputs, eliminating the need for a separate communication channel.
Credential and Data Exposure
The exposed attack toolkit included scripts for collecting browser and Windows credentials, testing SQL logins, and transferring files. Notably, Mimikatz artifacts indicated credential dumping activities, although no direct connection to similar past campaigns was established.
Researchers also found SQL Server Management Studio connection histories, database usernames, and password material protected by Windows DPAPI. These could potentially aid attackers in identifying further targets, though their presence does not guarantee successful decryption or misuse.
Collected source codes and configuration files referenced various systems and services, including OAuth, email, and payment integrations. ThreatMon has withheld sensitive details to prevent further exploitation.
Security Implications and Recommendations
Organizations are advised to scrutinize historical network connections against published indicators and inspect endpoints for matching hashes and directories. Immediate investigation is recommended for any unusual use of xp_cmdshell, encoded PowerShell, or atypical file operations under a SQL Server service account.
Stored database connections and password records should be treated as sensitive data, given the exposure risk. ThreatMon emphasizes that any credentials reaching the exposed server must be considered compromised, as they were accessible to unauthorized parties.
To enhance security, integrating threat intelligence tools can significantly reduce the time needed for Security Operations Center (SOC) alert investigations, providing immediate context and facilitating faster responses.
