INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Microsoft SQL Server Hijacked for Command and Data Exfiltration
| 2026-10-02 14:55 DATA BREACH
Executive Summary
AI-generated
Hackers turned a Microsoft SQL Server into an exfiltration channel, running commands and moving collected files in an intrusion linked to Viva Aerobus. The activity observed between September 25 and 29, 2026, involved credential harvesting and source code theft. This incident highlights the vulnerability of using publicly accessible servers as channels for malicious activities. A server compromised by hackers was then used to expose attack tools and stolen material to unrelated internet users. Notably, this exfiltration tactic (TACTIC) was executed by hackers turned Microsoft SQL Server into a command and data exfiltration channel, with the identified entity being Hackers Turned and Microsoft as the targeted organization. The incident is linked to Viva Aerobus environment, while Cyber Security News reported on it. The attack tools and stolen material were publicly exposed through this server, which was used by hackers turned Microsoft SQL Server into a command and data exfiltration channel between September 25 and 29, 2026.
Technical Mitigations AI-generated
• Implementing least privilege access for SQL Server to limit the damage in case of a breach
• Regularly monitoring and patching SQL Server to prevent exploitation of known vulnerabilities
• Using secure protocols such as TLS/SSL to encrypt data transmitted between the compromised server and external users
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
8b6c53••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
33aeaa••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
c38f49••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
th•••••.io
151.243.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Tactical Metrics
Intelligence Sources
AlienVault OTX
2026-10-02