Threat reportThreat IntelligenceTL-2026-2868
Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked Intrusion
Attackers Abuse Microsoft SQL Server xp_cmdshell as Command (TL-2026-2868), also tracked as Viva Aerobus-linked MSSQL intrusion, is a high-severity tracked intrusion set, first published 2026-10-03. It has no confirmed attribution, affects Microsoft SQL Server (xp_cmdshell enabled), maps to 12 MITRE ATT&CK techniques (T1003, T1005, T1021.002), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 12MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-2868
- Threat ID
- TL-2026-2868
- Also known as
- Viva Aerobus-linked MSSQL intrusion, artex toolkit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- aviation, transport
- Target regions
- mexico
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Attackers Abuse Microsoft SQL Server xp_cmdshell as Command
Malware and tooling: MimiKatz, Mimikatz, cmd - S0106
How Attackers Abuse Microsoft SQL Server xp_cmdshell as Command works
ThreatMon found an unauthenticated attacker staging/loot server (151.243.232.123) exposing a 17-item post-exploitation toolkit used against a Microsoft SQL Server in a Viva Aerobus-linked environment between 2026-09-25 and 2026-09-29. The actors ran OS commands and encoded PowerShell through xp_cmdshell, returned file contents as Base64 chunks in SQL query output, harvested credentials (Mimikatz, Credential Manager, browser, SSMS/DPAPI) and prepared lateral movement; the initial access vector is unknown and no downstream compromise or passenger-data theft is confirmed.
Between 2026-09-25 and 2026-09-29, a Microsoft SQL Server in an environment linked to Mexican airline Viva Aerobus was used as an execution platform and data channel. ThreatMon identified the attacker's exposed staging and loot server at 151.243.232.123 during routine threat hunting. The server was an unauthenticated HTTP host with open directory listings, so unrelated internet hosts could enumerate loot directories and retrieve the offensive tooling. ThreatMon's public report (published 2026-10-01) is intentionally sanitized; victim IPs, hostnames, user identities, credentials, OAuth identifiers and partner configurations are withheld.
Execution: recovered scripts use the SQL Server xp_cmdshell extended stored procedure, when enabled, to run Windows commands (cmd.exe) and Base64-encoded PowerShell under the SQL Server service account. Rather than deploy separate C2 infrastructure, the tooling (exfil.py, upload.py) reads files, splits them into chunks, Base64-encodes them and returns them through SQL query output, turning the database session into both a command and an exfiltration channel. The working directory on the victim host was C:\Windows\Temp\artex. Timeline per ThreatMon: on 2026-09-25 at 16:20 a victim-side MSSQL server retrieved a payload from the staging server; at 16:21-16:23 an unrelated external host enumerated the staging server and its loot directories; at 16:30 self-test requests came from the staging host; at 18:04-18:05 additional external hosts retrieved tooling.
Credential access and lateral-movement preparation: artifacts include Mimikatz output (mdump.txt), cred_dec.txt, scripts for Windows credential store, Credential Manager/Vault and browser credential extraction (cred_dump.ps1, cred_enum.ps1, vault.cmd, vtest.ps1, chrome_dump.ps1), SSMS connection history, database usernames and DPAPI-protected saved passwords. sqlspray.ps1 and mssqltest.ps1 tested username/password combinations against other SQL targets (checking login identity and server-role membership), and the utilities also checked access to SMB administrative shares. Source code and configuration files referencing SQL connections, OAuth, mail, SFTP, payment and reporting integrations were collected (loot/, loot2/).
Limits of the evidence: the investigation did not establish how the attackers first entered the environment; no named malware family was identified (it is described as a toolkit, not a single implant); no link to other known campaigns was established; and there is no evidence of successful access to additional systems or theft of sensitive passenger, payment or business data. One ThreatMon page lists the handles Blackhatsect0r and DXQRTXX in a threat-actor field, but the sources provide no attribution narrative, so attribution is recorded as Unknown/low confidence.
MITRE ATT&CK techniques used in TL-2026-2868
Credential Access
T1003 OS Credential Dumping; T1110.003 Brute Force: Password Spraying; T1552.001 Unsecured Credentials: Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers; T1555.004 Credentials from Password Stores: Windows Credential Manager
Collection
Lateral Movement
T1021.002 Remote Services: SMB/Windows Admin Shares
Defense Evasion
T1027 Obfuscated Files or Information
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell
Command and Control
T1132.001 Data Encoding: Standard Encoding
Persistence
Affected products and versions in Attackers Abuse Microsoft SQL Server xp_cmdshell as Command
- Microsoft — SQL Server (xp_cmdshell enabled)
Remediation for Attackers Abuse Microsoft SQL Server xp_cmdshell as Command
Immediate actions
- Review historical network telemetry for connections to 151.243.232.123 and block it at the perimeter
- Search endpoints for the published SHA256 hashes and for the C:\Windows\Temp\artex directory
- Investigate unexpected xp_cmdshell activation (sp_configure 'xp_cmdshell') and any use of it
- Alert on cmd.exe and powershell.exe (especially encoded commands) spawned by sqlservr.exe or the SQL Server service account
- Assume all credentials that reached the exposed attacker infrastructure are compromised and rotate database, OAuth, mail and SFTP secrets
Workarounds
- Disable xp_cmdshell where it is not required
- Restrict SQL Server and SMB administrative-share access between hosts
Longer-term hardening
- Run SQL Server service accounts with least privilege and restrict their outbound network access
- Treat SSMS metadata (connection history, saved credentials, DPAPI-protected passwords) as sensitive credential-adjacent data
- Do not store credentials or integration secrets in source code and configuration files
- Monitor for SQL logins from unexpected hosts and for password spraying across SQL servers
Timeline of Attackers Abuse Microsoft SQL Server xp_cmdshell as Command
- At 18:04-18:05 additional external hosts retrieved post-exploitation tools and artifacts from the open server
- At 16:30 self-test requests were observed originating from the staging host
- At 16:21-16:23 an unrelated external host enumerated the unauthenticated staging server and its loot directories
- At 16:20 a victim-side MSSQL server retrieved a payload from the attacker staging server 151.243.232.123; the intrusion window runs 2026-09-25 to 2026-09-29
- End of the activity window ThreatMon associates with the exposed server (xp_cmdshell execution, credential harvesting, lateral-movement preparation)
- ThreatMon published a sanitized report on the exposed staging server and 17-item toolkit found during routine threat hunting
- Cyber Security News and other outlets reported the SQL Server command and exfiltration channel; initial access remains unknown and no passenger-data theft is confirmed
Sources cited for Attackers Abuse Microsoft SQL Server xp_cmdshell as Command
- Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel
- An Open Server, an Exposed Toolkit Inside a Viva Aerobus-Linked Intrusion - ThreatMon
- Viva Aerobus-Linked Attacker Infrastructure and Post-Exploitation Findings - ThreatMon
- Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion - GBHackers
- MSSQL Post-Exploitation Toolkit Could Enable Credential Theft and Lateral Movement Attacks - Cyberpress
- SELECT XMRig FROM SQLServer - The DFIR Report (xp_cmdshell abuse context)
- MITRE ATT&CK T1505.001 SQL Stored Procedures
Detection coverage for TL-2026-2868
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2868 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.