# Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked Intrusion

> ThreatMon found an unauthenticated attacker staging/loot server (151.243.232.123) exposing a 17-item post-exploitation toolkit used against a Microsoft SQL Server in a Viva Aerobus-linked environment between 2026-09-25 and 2026-09-29. The actors ran OS commands and encoded PowerShell through xp_cmdshell, returned file contents as Base64 chunks in SQL query output, harvested credentials (Mimikatz, Credential Manager, browser, SSMS/DPAPI) and prepared lateral movement; the initial access vector is unknown and no downstream compromise or passenger-data theft is confirmed.

- **Published:** 2026-10-03T00:00:00Z
- **Last reviewed:** 2026-10-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2868
- **ID:** TL-2026-2868
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Between 2026-09-25 and 2026-09-29, a Microsoft SQL Server in an environment linked to Mexican airline Viva Aerobus was used as an execution platform and data channel. ThreatMon identified the attacker's exposed staging and loot server at 151.243.232.123 during routine threat hunting. The server was an unauthenticated HTTP host with open directory listings, so unrelated internet hosts could enumerate loot directories and retrieve the offensive tooling. ThreatMon's public report (published 2026-10-01) is intentionally sanitized; victim IPs, hostnames, user identities, credentials, OAuth identifiers and partner configurations are withheld.

Execution: recovered scripts use the SQL Server xp_cmdshell extended stored procedure, when enabled, to run Windows commands (cmd.exe) and Base64-encoded PowerShell under the SQL Server service account. Rather than deploy separate C2 infrastructure, the tooling (exfil.py, upload.py) reads files, splits them into chunks, Base64-encodes them and returns them through SQL query output, turning the database session into both a command and an exfiltration channel. The working directory on the victim host was C:\Windows\Temp\artex. Timeline per ThreatMon: on 2026-09-25 at 16:20 a victim-side MSSQL server retrieved a payload from the staging server; at 16:21-16:23 an unrelated external host enumerated the staging server and its loot directories; at 16:30 self-test requests came from the staging host; at 18:04-18:05 additional external hosts retrieved tooling.

Credential access and lateral-movement preparation: artifacts include Mimikatz output (mdump.txt), cred_dec.txt, scripts for Windows credential store, Credential Manager/Vault and browser credential extraction (cred_dump.ps1, cred_enum.ps1, vault.cmd, vtest.ps1, chrome_dump.ps1), SSMS connection history, database usernames and DPAPI-protected saved passwords. sqlspray.ps1 and mssqltest.ps1 tested username/password combinations against other SQL targets (checking login identity and server-role membership), and the utilities also checked access to SMB administrative shares. Source code and configuration files referencing SQL connections, OAuth, mail, SFTP, payment and reporting integrations were collected (loot/, loot2/).

Limits of the evidence: the investigation did not establish how the attackers first entered the environment; no named malware family was identified (it is described as a toolkit, not a single implant); no link to other known campaigns was established; and there is no evidence of successful access to additional systems or theft of sensitive passenger, payment or business data. One ThreatMon page lists the handles Blackhatsect0r and DXQRTXX in a threat-actor field, but the sources provide no attribution narrative, so attribution is recorded as Unknown/low confidence.

## MITRE ATT&CK

- T1505.001 Server Software Component: SQL Stored Procedures
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1027 Obfuscated Files or Information
- T1132.001 Data Encoding: Standard Encoding
- T1003 OS Credential Dumping
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1555.004 Credentials from Password Stores: Windows Credential Manager
- T1552.001 Unsecured Credentials: Credentials In Files
- T1110.003 Brute Force: Password Spraying
- T1005 Data from Local System
- T1021.002 Remote Services: SMB/Windows Admin Shares

## Sources

- [Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel](https://cybersecuritynews.com/hackers-turned-a-microsoft-sql-server/)
- [An Open Server, an Exposed Toolkit Inside a Viva Aerobus-Linked Intrusion - ThreatMon](https://threatmon.io/an-open-server-an-exposed-toolkit-inside-a-viva-aerobus-linked-intrusion/)
- [Viva Aerobus-Linked Attacker Infrastructure and Post-Exploitation Findings - ThreatMon](https://threatmon.io/viva-aerobus-linked-attacker-infrastructure-and-post-exploitation-findings/)
- [Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion - GBHackers](https://gbhackers.com/viva-aerobus-intrusion/)
- [MSSQL Post-Exploitation Toolkit Could Enable Credential Theft and Lateral Movement Attacks - Cyberpress](https://cyberpress.org/mssql-toolkit-threatens-credentials/)
- [SELECT XMRig FROM SQLServer - The DFIR Report (xp_cmdshell abuse context)](https://thedfirreport.com/?p=8036)
- [MITRE ATT&CK T1505.001 SQL Stored Procedures](https://attack.mitre.org/techniques/T1505/001/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2868
