VYPR
breachPublished Oct 2, 2026· 1 source

Hackers Weaponize Microsoft SQL Server for Command and Control

Attackers exploited a Microsoft SQL Server's xp_cmdshell feature to execute commands and exfiltrate data, turning the database into a covert command and control channel.

In a sophisticated post-compromise operation, threat actors transformed a Microsoft SQL Server instance into a dual-purpose tool for executing commands and exfiltrating sensitive files. The incident, observed between September 25 and 29, 2026, targeted an environment linked to Viva Aerobus, allowing attackers to harvest credentials, steal source code, and lay the groundwork for further system access.

Researchers from ThreatMon discovered an exposed server belonging to the attackers, which inadvertently revealed a trove of 17 distinct tools and stolen data. This unusual transparency offered a detailed glimpse into the attackers' post-exploitation activities, although the initial entry vector into the compromised environment remains unknown. The investigation did not uncover evidence of a passenger data breach or successful lateral movement to other critical systems.

The core of the attack leveraged the xp_cmdshell feature within Microsoft SQL Server. When enabled, this feature allows the execution of operating system commands. The attackers utilized this capability to submit Windows commands and encoded PowerShell scripts through database sessions, effectively turning the SQL Server into a gateway to the underlying operating system. This technique is not entirely new, as similar methods have been observed in other SQL Server attacks, but the recovered evidence here focuses on the post-compromise phase.

Beyond command execution, the compromised SQL Server was also used as a channel for data exfiltration. The attackers employed a method where file contents were read, segmented into smaller pieces, encoded using Base64, and then transmitted back through SQL query outputs. This approach bypassed the need for a conventional command and control (C2) server, as all communication, including data transfer, occurred within the existing database connection.

The exposed staging server contained a variety of tools designed for credential harvesting, including scripts for extracting browser and Windows credentials, testing SQL logins, and facilitating file transfers. Evidence of Mimikatz artifacts pointed to credential dumping activities, a technique also seen in other campaigns, though no direct link was established. Additionally, recovered SQL Server Management Studio connection histories and saved password material protected by Windows DPAPI suggested attempts to reuse credentials and move laterally across the network.

Among the exfiltrated data were source code and configuration files referencing various integrations, including database connections, OAuth, email, SFTP, and payment processing systems. ThreatMon opted to withhold sensitive details like hostnames and usernames from their public report to prevent further compromise. The recovered utilities also included tools for testing credentials against other SQL systems and probing SMB administrative shares, indicating a clear intent to expand their access.

While the attackers successfully established a command and control channel via the SQL Server and exfiltrated various data types, researchers found no definitive proof of successful access to additional systems or the theft of sensitive passenger, payment, or business data. The incident highlights the critical importance of securing database configurations, monitoring for unexpected xp_cmdshell usage, and investigating suspicious file operations or encoded PowerShell activity within SQL Server environments.

Defenders are urged to review historical network connections against the provided indicators of compromise (IoCs) and search endpoints for matching file hashes and the reported working directory. The exposure of credentials or secrets to the attacker's staging server means they should be considered compromised, as unrelated parties also accessed this material.

Synthesized by Vypr AI