October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Redmond desk3 min

How Hackers Used Microsoft SQL Server to Run Commands and Move Data

ThreatMon says attackers used SQL sessions for Windows commands and Base64 file transfer in activity linked to a Viva Aerobus-side environment. The exposed staging server also let unrelated hosts access tools and collected material.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a September 2026 incident linked by ThreatMon to a Viva Aerobus-side environment, attackers used Microsoft SQL Server as both a route for operating-system commands and a way to return collected file contents. The activity relied on xp_cmdshell and SQL query output—not a demonstrated SQL Server vulnerability exploit. The attacker’s own unauthenticated staging server was also publicly exposed, allowing unrelated internet hosts to access its tools and collected material.

How SQL Server became a command channel

ThreatMon described post-compromise activity spanning September 25–29, 2026. Recovered tooling submitted Windows commands and Base64-encoded PowerShell through SQL sessions. It used xp_cmdshell, an extended stored procedure that can run operating-system commands when enabled.

As an Amazon Associate I earn from qualifying purchases.

The same SQL route was used to read files, split their contents into chunks, encode those chunks as Base64 text, and return them in query output. That let the existing database session carry commands and collected data without requiring a separate conventional command-and-control connection for that transfer. Base64 is an encoding, not encryption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft says xp_cmdshell is disabled by default on new SQL Server installations. Its current guidance, on a Learn page updated August 24, 2026, says: “Newly developed code shouldn’t use the xp_cmdshell stored procedure and generally it should be left disabled.” For a legacy application that requires it, Microsoft recommends enabling it only for the duration of the task. Microsoft Learn: Server configuration: xp_cmdshell.

What the exposed server revealed

ThreatMon said the attacker-controlled HTTP staging server held 17 named post-exploitation tools. The server had no authentication and was reachable from the public internet. The tools included browser and Windows credential collection scripts, credential-enumeration utilities, SQL-login testing and file-transfer scripts, and tools associated with Windows Credential Manager or Vault access.

Investigators also reported Mimikatz-related artifacts, SSMS connection history, database usernames, and saved-password material protected by Windows DPAPI. DPAPI protection does not establish that every saved password was decrypted. Source code and configuration files referenced SQL, OAuth, email, SFTP, and payment or reporting integrations; ThreatMon withheld sensitive values and victim-specific details from public release.

The recovered toolset and material indicate credential harvesting and preparation to try credentials against other SQL systems and SMB administrative shares. They do not establish that those other systems were successfully compromised.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the staging-server exposure mattered

The infrastructure’s exposure created a second risk beyond the activity against the linked environment: other parties could reach the attacker’s tools and material already collected from the victim-side system. ThreatMon’s HTTP records show the sequence below; these are event timestamps, not prevalence statistics.

Time on September 25, 2026 Activity reported by ThreatMon
16:20 A victim-side Microsoft SQL Server retrieved a payload from the attacker’s infrastructure.
16:21–16:23 An unrelated external host enumerated the staging server.
18:04–18:05 Additional external hosts retrieved tooling or artifacts.

What is—and is not—confirmed

The reporting describes activity linked to a Viva Aerobus-side environment, but it does not establish how the attackers first entered that environment. It also does not identify a named malware family or prove successful lateral movement. The available account supports credential, connection-metadata, and source-code/configuration collection, alongside preparation for possible credential reuse.

ThreatMon reported no evidence confirming theft of sensitive passenger, payment, or equivalent business data. It would therefore be inaccurate to say passenger data was stolen or that additional systems were breached. The incident should be understood as observed post-compromise activity, not as a confirmed SQL Server vulnerability exploit or a proven company-wide breach.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to check whether xp_cmdshell is being abused

Investigate the setting and activity in context. A legitimate legacy task may require temporary use, but unexpected activation or use warrants review—especially when database activity coincides with operating-system processes or unusual file access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Review configuration and change history. Determine whether xp_cmdshell is enabled, why it is needed, who enabled it, and whether its use was limited to a specific task. Microsoft’s general recommendation is to leave it disabled and enable it temporarily only when a legacy task requires it.
  • Correlate database and endpoint telemetry. Look for unexpected cmd.exe or PowerShell activity under a SQL Server service identity, encoded commands, unusual file reads, or other unexpected child processes alongside database command execution.
  • Check relevant indicators carefully. ThreatMon published an attacker-side address, file hashes, and a working directory. Search available endpoint and historical network telemetry for those indicators, validating them in a controlled security workflow before using them operationally. The report does not establish that every indicator will appear in other environments.
  • Review credential-adjacent material. Treat saved SSMS connection history, database usernames, and DPAPI-protected password material as sensitive. If credentials are known to have reached exposed infrastructure, review and rotate them under your organization’s incident-response procedures.
  • Preserve evidence. Retain relevant logs and endpoint and database records while investigating. The published detection points are not a complete response playbook.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.