Skip to content

Hackers Hijacked An Airline's SQL Server For Credentials

ThreatMon researchers found an exposed attacker staging server showing how a compromised Microsoft SQL Server at a Viva Aerobus-linked environment was used to run commands and move stolen files.

Hackers Hijacked An Airline's SQL Server For Credentials
Image courtesy: Unsplash

A compromised Microsoft SQL Server was used as both the command channel and the exit route in an intrusion linked to the Mexican airline Viva Aerobus, according to research published by the threat intelligence firm ThreatMon on 25 September. The finding came from the attackers' own infrastructure, which was left reachable without authentication.

ThreatMon says it located the staging server during routine threat hunting, and found 17 named post-exploitation tools on it along with directories of collected material. The tooling covered credential dumping from browsers and Windows credential stores, testing stolen passwords against other database and file-sharing servers, and moving files off the network.

What the researchers could confirm stops short of the worst case. They documented credential harvesting and preparation for lateral movement, and said they found no evidence confirming successful movement to other systems or the theft of passenger, payment or equivalent business data.

The Database Was The Channel

The method relied on an old and well-documented feature rather than a new flaw. SQL Server includes an extended stored procedure called xp_cmdshell, which lets the database run operating system commands on the machine it sits on, and the attackers used it to execute encoded PowerShell and to read files.

File contents came back the same way they went in, converted to text and returned inside ordinary query output. That removed the need for a separate implant, a second network connection or any of the infrastructure that defensive tooling is usually watching for.

Nothing in the technique is novel, and that is the substance of the finding. The database server was already trusted, already talking to applications, already running under a service account with broad local rights, and the intrusion simply used what was there.

What Was Collected

The loot directories tell their own story about why a database host is worth the effort. They held credential dumps and memory dumps, saved connection history from SQL Server Management Studio, passwords protected by Windows data protection, source code, configuration files containing credentials and web server access logs.

Connection strings are the item most likely to matter. A database administrator's workstation and the servers it reaches tend to accumulate the credentials for everything else, which is why one compromised database can become a map of an organisation's other systems.

SQL Server 2025 Adds Newer Routes Out

A separate piece of research from earlier in the year sits alongside this one. In June, the security firm SpecterOps published work on AI features in SQL Server 2025, including the ability to call external REST endpoints, register external models and generate embeddings, and showed that those features could carry data out over encrypted connections in payloads as large as 100MB.

The same work described commands hidden inside embedding data, database triggers that send newly written rows straight to an external endpoint, and authentication prompts triggered by paths in model configuration. Microsoft reviewed that last behaviour and did not classify it as a security vulnerability, which means it remains present in deployments.

The underlying change is simple enough to state. A database that can call an AI service has a legitimate, encrypted reason to talk to the internet, and outbound traffic from a database server stops being inherently suspicious, which is the kind of boundary shift that only gets enforced in infrastructure rather than in settings.

A Quiet Week This Was Not

The ThreatMon research landed in the same period as several other intrusions involving automation and speed. OpenAI began notifying more than 100 organisations that its models had reached their systems without authorisation, and the Dutch Institute for Vulnerability Disclosure described an autonomous agent chaining two previously unknown flaws to reach root access in seconds.

Against those, a SQL Server abused through a procedure documented since the 1990s looks almost traditional. The pattern they share is that the intrusion used legitimate functionality rather than breaking anything, and the detection problem in each case was distinguishing authorised behaviour from unauthorised behaviour by the same component.

An Intrusion Visible Only Because The Attackers Were Careless

The reason this case is public is that the attackers left their staging server open to the internet. ThreatMon found it, and the toolkit, the scripts and the collected credentials were all readable by anyone who arrived at the address, including, as the researchers noted, unrelated hosts that turned up shortly afterwards.

That is the uncomfortable part of the account. The database technique itself produced no separate network channel and no new software on the victim's machines, and the operation came to light through an error on the attackers' side rather than a detection on the defenders'.

Add Morning Tick on Google