Detailed Insight Into a Rapid Intrusion Linked to Viva Aerobus
A recently uncovered attack staging server has shed light on a sophisticated intrusion targeting a Microsoft SQL Server environment associated with Viva Aerobus. This server, accessible at the IP address 151.243.232.123, served dual purposes: it was both a delivery point for malicious tools and a repository for exploitable materials that compromised security.
The alarming aspect of this incident is that the server was found to be open and lacking any form of authentication. This vulnerability allowed various unrelated hosts across the internet to navigate its directories and download harmful tools shortly after a victim situated in a Microsoft SQL Server environment retrieved a payload from the same compromised infrastructure.
ThreatMon, a threat intelligence research organization, made this alarming discovery while conducting routine threat-hunting operations. They were able to reconstruct a workflow that highlighted activities centered around executing MSSQL commands, gaining access to credentials, staging data, and preparing for potential reuse of those credentials across additional SQL Server and SMB (Server Message Block) targets.
The intrusion utilized Microsoft SQL Server as a platform for executing malicious activities, specifically employing the stored procedure known as xp_cmdshell. When enabled, this procedure allows for the execution of operating system commands directly from an SQL Server session, thereby providing attackers with broader capabilities to infiltrate operating environments.
On September 25, at precisely 16:20, a victim’s MSSQL server accessed a payload from the attacker-controlled server. Subsequent investigations revealed that the attackers effectively leveraged xp_cmdshell to run Windows commands and Base64-encoded PowerShell scripts, potentially under the privileges of the SQL Server service account. This method can pose severe risks, particularly in scenarios where database servers manage privileged credentials, contain crucial connection strings, or provide access to internal file shares. Moreover, it alleviates the attackers’ need to install traditional malware or establish a separate command-and-control channel.
The tools recovered from the exposed server indicated they had the capability to read files, segment them into Base64-encoded chunks, and transmit the content through SQL query outputs. This technique allowed for data exfiltration via an existing SQL execution path, sidestepping the need for a new outbound network connection.
It is crucial for organizations to monitor and treat any anomalous activity involving xp_cmdshell, especially executions of commands such as cmd.exe or powershell.exe, as a high-priority detection and incident-response trigger. The exposed server contained 17 named post-exploitation tools and associated artifacts, including scripts like chrome_dump.ps1, cred_dump.ps1, and cred_enum.ps1. These tools were specifically designed to extract credentials from various storage systems, including browser stores and Windows Credential Manager.
Other utilities, such as sqlspray.ps1 and mssqltest.ps1, were also discovered, targeting SQL Server for credential testing. Additionally, scripts labeled exfil.py and upload.py facilitated the transfer of files, while vault.cmd and vtest.ps1 were likely intended for accessing Windows Credential Manager or Vault.
ThreatMon researchers noted that by September 25, 2026, this unauthenticated server had been exposed, revealing post-exploitation tools, credential-dumping outputs, and SQL Server Management Studio (SSMS) artifacts along with files seemingly gathered during operations.
In an attempt to bolster cybersecurity defenses, ThreatMon shared SHA-256 indicators for the key scripts, enabling security professionals to track file matches more effectively rather than relying solely on potentially altered file names. Credential access strategies employed by the attackers included the use of Mimikatz, PowerShell scripts for browser credential theft, targeting Windows Credential Manager, and attempts to recover data protected by the Data Protection API (DPAPI).
Further investigations into SSMS user settings unveiled historical SQL Server connections, database usernames, and safeguarded password data that could intricately map the internal database landscape for the attackers. Although ThreatMon did not disclose any victim-specific hostnames or sensitive content, the findings indicated a thorough effort by the attackers to unearth embedded secrets and service credentials, which could pave the way for broader access.
The researchers found scripts designed to test SQL credentials, enumerate effective login identities, and check for SMB administrative-share access. Although no conclusive evidence of lateral movement, access to additional systems, or the exfiltration of sensitive data was noted, the activities indicated a potential preparation for credential harvesting and lateral movement.
Intriguingly, the incident served as a potent reminder of how failures in operational security can lead to multiple compromise events. Just moments after the victim-side payload was retrieved, unrelated external hosts began to explore the exposed staging server and its directories. This activity indicates that the breach may have lifted the curtain on additional vulnerabilities.
Moving forward, security teams are advised to scrutinize any suspicious MSSQL activity, disable xp_cmdshell wherever it’s unnecessary, rotate any compromised database credentials, and review the privileges associated with SQL Server service accounts and their outbound connections.
Ultimately, this incident underscores a critical defensive lesson: exposed infrastructure wielded by attackers can serve as a crucible of compromised tools, credentials, files, and intelligence that malicious actors might exploit, thereby creating significant risks for various organizations.
