Threat reportThreat IntelligenceTL-2026-2868

Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked Intrusion

highACTIVE

Attackers Abuse Microsoft SQL Server xp_cmdshell as Command (TL-2026-2868), also tracked as Viva Aerobus-linked MSSQL intrusion, is a high-severity tracked intrusion set, first published 2026-10-03. It has no confirmed attribution, affects Microsoft SQL Server (xp_cmdshell enabled), maps to 12 MITRE ATT&CK techniques (T1003, T1005, T1021.002), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-2868

Threat ID
TL-2026-2868
Also known as
Viva Aerobus-linked MSSQL intrusion, artex toolkit
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
aviation, transport
Target regions
mexico
Detection rules
9
Indicators of compromise
20

Malware and tooling in Attackers Abuse Microsoft SQL Server xp_cmdshell as Command

Malware and tooling: MimiKatz, Mimikatz, cmd - S0106

How Attackers Abuse Microsoft SQL Server xp_cmdshell as Command works

ThreatMon found an unauthenticated attacker staging/loot server (151.243.232.123) exposing a 17-item post-exploitation toolkit used against a Microsoft SQL Server in a Viva Aerobus-linked environment between 2026-09-25 and 2026-09-29. The actors ran OS commands and encoded PowerShell through xp_cmdshell, returned file contents as Base64 chunks in SQL query output, harvested credentials (Mimikatz, Credential Manager, browser, SSMS/DPAPI) and prepared lateral movement; the initial access vector is unknown and no downstream compromise or passenger-data theft is confirmed.

Between 2026-09-25 and 2026-09-29, a Microsoft SQL Server in an environment linked to Mexican airline Viva Aerobus was used as an execution platform and data channel. ThreatMon identified the attacker's exposed staging and loot server at 151.243.232.123 during routine threat hunting. The server was an unauthenticated HTTP host with open directory listings, so unrelated internet hosts could enumerate loot directories and retrieve the offensive tooling. ThreatMon's public report (published 2026-10-01) is intentionally sanitized; victim IPs, hostnames, user identities, credentials, OAuth identifiers and partner configurations are withheld.

Execution: recovered scripts use the SQL Server xp_cmdshell extended stored procedure, when enabled, to run Windows commands (cmd.exe) and Base64-encoded PowerShell under the SQL Server service account. Rather than deploy separate C2 infrastructure, the tooling (exfil.py, upload.py) reads files, splits them into chunks, Base64-encodes them and returns them through SQL query output, turning the database session into both a command and an exfiltration channel. The working directory on the victim host was C:\Windows\Temp\artex. Timeline per ThreatMon: on 2026-09-25 at 16:20 a victim-side MSSQL server retrieved a payload from the staging server; at 16:21-16:23 an unrelated external host enumerated the staging server and its loot directories; at 16:30 self-test requests came from the staging host; at 18:04-18:05 additional external hosts retrieved tooling.

Credential access and lateral-movement preparation: artifacts include Mimikatz output (mdump.txt), cred_dec.txt, scripts for Windows credential store, Credential Manager/Vault and browser credential extraction (cred_dump.ps1, cred_enum.ps1, vault.cmd, vtest.ps1, chrome_dump.ps1), SSMS connection history, database usernames and DPAPI-protected saved passwords. sqlspray.ps1 and mssqltest.ps1 tested username/password combinations against other SQL targets (checking login identity and server-role membership), and the utilities also checked access to SMB administrative shares. Source code and configuration files referencing SQL connections, OAuth, mail, SFTP, payment and reporting integrations were collected (loot/, loot2/).

Limits of the evidence: the investigation did not establish how the attackers first entered the environment; no named malware family was identified (it is described as a toolkit, not a single implant); no link to other known campaigns was established; and there is no evidence of successful access to additional systems or theft of sensitive passenger, payment or business data. One ThreatMon page lists the handles Blackhatsect0r and DXQRTXX in a threat-actor field, but the sources provide no attribution narrative, so attribution is recorded as Unknown/low confidence.

MITRE ATT&CK techniques used in TL-2026-2868

Credential Access

T1003 OS Credential Dumping; T1110.003 Brute Force: Password Spraying; T1552.001 Unsecured Credentials: Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers; T1555.004 Credentials from Password Stores: Windows Credential Manager

Collection

T1005 Data from Local System

Lateral Movement

T1021.002 Remote Services: SMB/Windows Admin Shares

Defense Evasion

T1027 Obfuscated Files or Information

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell

Command and Control

T1132.001 Data Encoding: Standard Encoding

Persistence

T1505.001 Server Software Component: SQL Stored Procedures

Affected products and versions in Attackers Abuse Microsoft SQL Server xp_cmdshell as Command

  • Microsoft — SQL Server (xp_cmdshell enabled)

Remediation for Attackers Abuse Microsoft SQL Server xp_cmdshell as Command

Immediate actions

  • Review historical network telemetry for connections to 151.243.232.123 and block it at the perimeter
  • Search endpoints for the published SHA256 hashes and for the C:\Windows\Temp\artex directory
  • Investigate unexpected xp_cmdshell activation (sp_configure 'xp_cmdshell') and any use of it
  • Alert on cmd.exe and powershell.exe (especially encoded commands) spawned by sqlservr.exe or the SQL Server service account
  • Assume all credentials that reached the exposed attacker infrastructure are compromised and rotate database, OAuth, mail and SFTP secrets

Workarounds

  • Disable xp_cmdshell where it is not required
  • Restrict SQL Server and SMB administrative-share access between hosts

Longer-term hardening

  • Run SQL Server service accounts with least privilege and restrict their outbound network access
  • Treat SSMS metadata (connection history, saved credentials, DPAPI-protected passwords) as sensitive credential-adjacent data
  • Do not store credentials or integration secrets in source code and configuration files
  • Monitor for SQL logins from unexpected hosts and for password spraying across SQL servers

Timeline of Attackers Abuse Microsoft SQL Server xp_cmdshell as Command

  • At 18:04-18:05 additional external hosts retrieved post-exploitation tools and artifacts from the open server
  • At 16:30 self-test requests were observed originating from the staging host
  • At 16:21-16:23 an unrelated external host enumerated the unauthenticated staging server and its loot directories
  • At 16:20 a victim-side MSSQL server retrieved a payload from the attacker staging server 151.243.232.123; the intrusion window runs 2026-09-25 to 2026-09-29
  • End of the activity window ThreatMon associates with the exposed server (xp_cmdshell execution, credential harvesting, lateral-movement preparation)
  • ThreatMon published a sanitized report on the exposed staging server and 17-item toolkit found during routine threat hunting
  • Cyber Security News and other outlets reported the SQL Server command and exfiltration channel; initial access remains unknown and no passenger-data theft is confirmed

Sources cited for Attackers Abuse Microsoft SQL Server xp_cmdshell as Command

Detection coverage for TL-2026-2868

As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2868 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats