Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Attackers Abuse SQL Server as a Covert Command and Exfiltration Channel
Attackers Abuse SQL Server as a Covert Command and Exfiltration Channel
Read Time:3 Minute, 33 Second

Attackers investigating a Viva Aerobus environment turned a Microsoft SQL Server connection into a channel for operating-system commands and data theft, according to newly disclosed threat research. The intrusion shows how legitimate database functionality can become a covert control path after credentials or access have already been obtained.

The activity was observed from September 25 through September 29, 2026. Researchers recovered evidence of credential collection, source-code gathering and attempts to prepare access to other systems. The initial entry point has not been established, and the available evidence does not prove a passenger-data or payment-data breach.

An unusual operational mistake gave defenders a close look at the campaign: the attackers left their own server publicly accessible. It contained tools and collected files that could be retrieved by unrelated internet users, creating a second exposure on top of the original compromise.

Database access becomes operating-system control

The intruders relied on xp_cmdshell, an SQL Server feature capable of launching commands through Windows when it is enabled and sufficiently privileged. Recovered utilities submitted ordinary command-line instructions and encoded PowerShell through database sessions. That transformed a database connection into an interface for the host beneath it.

The technique does not by itself reveal how the attackers first gained access. There is no confirmed software vulnerability, password-spraying event or named malware family tied to the initial compromise. What the evidence does show is post-compromise abuse: once the SQL path was available, the attackers no longer needed a conventional remote-access implant for every action.

Defenders sometimes monitor databases principally for destructive queries, suspicious account creation or bulk record access. This incident highlights a wider requirement. Process creation under an SQL Server service account, especially cmd.exe or powershell.exe, can signal that database privileges are being converted into host control.

Files moved through query responses

The same connection also carried data outward. Tools read files, split them into smaller blocks, converted those blocks to Base64 text and returned the encoded content through SQL query results. Base64 provides no confidentiality; it simply represents binary data as text. In this case it allowed stolen material to fit naturally inside database responses.

Using an established database channel can help activity blend into expected network flows. Security controls focused on new command-and-control domains or unusual outbound protocols may miss exfiltration when the traffic travels between systems already permitted to communicate. Detection therefore needs behavioral context, including abnormal query size, repeated encoded output and file operations performed by database processes.

Credential collection and lateral-movement preparation

The exposed server held 17 named tools. They included scripts for extracting browser and Windows credentials, testing SQL logins, accessing Windows credential stores and transferring files. Mimikatz artifacts indicated credential-dumping activity, while SQL Server Management Studio history revealed database usernames and saved password material protected by Windows DPAPI.

Collected source code and configuration data referenced OAuth, email, SFTP, database, payment and reporting integrations. Such material can disclose architecture and secret locations even when every credential is not immediately usable. Investigators also found utilities designed to test credentials against additional SQL servers and probe SMB administrative shares.

Those artifacts support an assessment that the attackers were preparing to move laterally, but they do not prove that each attempted target was compromised. Researchers withheld private hostnames, usernames and reusable values rather than amplifying the leak. Any secret that reached the exposed staging server should nevertheless be considered compromised because third parties accessed its contents.

Detection and containment priorities

  • Investigate unexpected use or enablement of xp_cmdshell.
  • Hunt for encoded PowerShell and command shells launched by SQL Server service accounts.
  • Review large or repetitive query responses that could contain Base64 file chunks.
  • Rotate database, OAuth, email, SFTP and integration secrets present in exposed files.
  • Check SQL login testing, SMB admin-share access and unusual connections to other servers.

Organizations should also minimize SQL service-account privileges and disable risky features where business needs do not require them. Network segmentation must account for what a database server can reach after compromise, not only who can connect to it. The incident is a reminder that trusted administrative channels can become effective attacker infrastructure without introducing a distinctive malware protocol.

Source: Cyber Security News, reporting on ThreatMon’s investigation.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Attackers Abuse SQL Server as a Covert Command and Exfiltration Channel, use the discussion on Forum.

>> forum community

Comments

Leave a Reply