In a September 2026 incident linked by ThreatMon to a Viva Aerobus-side environment, attackers used Microsoft SQL Server as both a route for operating-system commands and a way to return collected file contents. The activity relied on xp_cmdshell and SQL query output—not a demonstrated SQL Server vulnerability exploit. The attacker’s own unauthenticated staging server was also publicly exposed, allowing unrelated internet hosts to access its tools and collected material.
How SQL Server became a command channel
ThreatMon described post-compromise activity spanning September 25–29, 2026. Recovered tooling submitted Windows commands and Base64-encoded PowerShell through SQL sessions. It used xp_cmdshell, an extended stored procedure that can run operating-system commands when enabled.
As an Amazon Associate I earn from qualifying purchases.
The same SQL route was used to read files, split their contents into chunks, encode those chunks as Base64 text, and return them in query output. That let the existing database session carry commands and collected data without requiring a separate conventional command-and-control connection for that transfer. Base64 is an encoding, not encryption.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchMicrosoft says xp_cmdshell is disabled by default on new SQL Server installations. Its current guidance, on a Learn page updated August 24, 2026, says: “Newly developed code shouldn’t use the xp_cmdshell stored procedure and generally it should be left disabled.” For a legacy application that requires it, Microsoft recommends enabling it only for the duration of the task. Microsoft Learn: Server configuration: xp_cmdshell.
#1 Best Overall
What the exposed server revealed
ThreatMon said the attacker-controlled HTTP staging server held 17 named post-exploitation tools. The server had no authentication and was reachable from the public internet. The tools included browser and Windows credential collection scripts, credential-enumeration utilities, SQL-login testing and file-transfer scripts, and tools associated with Windows Credential Manager or Vault access.
Investigators also reported Mimikatz-related artifacts, SSMS connection history, database usernames, and saved-password material protected by Windows DPAPI. DPAPI protection does not establish that every saved password was decrypted. Source code and configuration files referenced SQL, OAuth, email, SFTP, and payment or reporting integrations; ThreatMon withheld sensitive values and victim-specific details from public release.
Rank #2
The recovered toolset and material indicate credential harvesting and preparation to try credentials against other SQL systems and SMB administrative shares. They do not establish that those other systems were successfully compromised.
Free tools Windows power users keep installed
One-click scans. No signup required.
Why the staging-server exposure mattered
The infrastructure’s exposure created a second risk beyond the activity against the linked environment: other parties could reach the attacker’s tools and material already collected from the victim-side system. ThreatMon’s HTTP records show the sequence below; these are event timestamps, not prevalence statistics.
Rank #3
| Time on September 25, 2026 | Activity reported by ThreatMon |
|---|---|
| 16:20 | A victim-side Microsoft SQL Server retrieved a payload from the attacker’s infrastructure. |
| 16:21–16:23 | An unrelated external host enumerated the staging server. |
| 18:04–18:05 | Additional external hosts retrieved tooling or artifacts. |
What is—and is not—confirmed
The reporting describes activity linked to a Viva Aerobus-side environment, but it does not establish how the attackers first entered that environment. It also does not identify a named malware family or prove successful lateral movement. The available account supports credential, connection-metadata, and source-code/configuration collection, alongside preparation for possible credential reuse.
ThreatMon reported no evidence confirming theft of sensitive passenger, payment, or equivalent business data. It would therefore be inaccurate to say passenger data was stolen or that additional systems were breached. The incident should be understood as observed post-compromise activity, not as a confirmed SQL Server vulnerability exploit or a proven company-wide breach.
Rank #4
How to check whether xp_cmdshell is being abused
Investigate the setting and activity in context. A legitimate legacy task may require temporary use, but unexpected activation or use warrants review—especially when database activity coincides with operating-system processes or unusual file access.
Quick Recap
Best Value
- Review configuration and change history. Determine whether
xp_cmdshellis enabled, why it is needed, who enabled it, and whether its use was limited to a specific task. Microsoft’s general recommendation is to leave it disabled and enable it temporarily only when a legacy task requires it. - Correlate database and endpoint telemetry. Look for unexpected
cmd.exeor PowerShell activity under a SQL Server service identity, encoded commands, unusual file reads, or other unexpected child processes alongside database command execution. - Check relevant indicators carefully. ThreatMon published an attacker-side address, file hashes, and a working directory. Search available endpoint and historical network telemetry for those indicators, validating them in a controlled security workflow before using them operationally. The report does not establish that every indicator will appear in other environments.
- Review credential-adjacent material. Treat saved SSMS connection history, database usernames, and DPAPI-protected password material as sensitive. If credentials are known to have reached exposed infrastructure, review and rotate them under your organization’s incident-response procedures.
- Preserve evidence. Retain relevant logs and endpoint and database records while investigating. The published detection points are not a complete response playbook.
Sources
- ThreatMon’s October 1, 2026 incident investigation.
- Microsoft Learn: Server configuration: xp_cmdshell.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




