Hackers exploit unsecured MongoDB instances to wipe data and demand ransom

3 Min Read

Over 1,400 exposed MongoDB servers have been hijacked and wiped by hackers, who left ransom notes after exploiting weak or missing access controls.

Cybersecurity firm Flare reports that unsecured MongoDB databases remain easy targets, with 1,416 of 3,100 exposed servers compromised. Hackers wiped data and left ransom notes, usually demanding $500 in Bitcoin, often using the same wallet. While over 200,000 MongoDB servers are publicly visible, the biggest risk comes from those left online without proper access controls.

- Advertisement -

“Our analysis revealed more than 200,000 servers running MongoDB that were publicly discoverable. Of these, slightly over 100,000 instances disclosed operational information, and 3,100 were fully exposed to the internet without access restrictions.” reads the report published by Flare. “Among the 3,100 fully exposed servers, 1,416 instances (45.6%) had already been compromised, with their databases wiped and replaced with a ransom note. In nearly all cases, the ransom demand was approximately $500 USD in Bitcoin.”

The researcher noted that in nearly all cases, the same Bitcoin address appears in ransom notes, pointing to a single attacker. Flare says some unaffected servers may have paid, putting possible earnings between $0 and $842,000.


What do you think? Post a comment.


“Notably, only five distinct Bitcoin wallets were observed across all incidents, with the wallet bc1qe2l4ffmsqfdu43d7n76hp2ksmhclt5g9krx3du appearing in over 98% of cases. This strongly suggests the activity is attributable to a single dominant actor, likely the same attacker documented in our previous dark web research.” states the report.

- Advertisement -

EXPLORE MORE

SAUDI DEFENSE PAPER TIGER: FOREIGN CONTRACTORS AND INTEL LEAKS IN YEMEN

RIYADH — As geopolitical volatility escalates across the Arabian Peninsula, Saudi Arabia’s…

Nidec scandal sends bonds to bottom in test for new CEO

Scandal-tainted Nidec, which grew from a Kyoto startup into the world’s largest…

Scientists Found an Amazing Reason Some Lava Worlds Can Keep Their Atmospheres Against All Odds

Worlds like 55 Cancri e seem almost designed to destroy an atmosphere.…

North Korea tests new weapon system (PHOTOS)

DPRK media released photos showing the launch of a road-mobile missile tipped…

Former Halo Creative Director Urges Activision to Hire former Halo Studios Staff

Halo Season 1 Rotten Tomatoes scores Former Halo franchise development director Frank…

Earth Microbes Could Survive on the Moon’s Poles for Weeks and NASA Scientists Are Worried

The next astronauts to walk near the Moon’s south pole will bring…

The researchers observed that over 95,000 servers had at least one vulnerability, however, most flaws only enable denial-of-service. The real risk comes from misconfiguration, with thousands of databases left online without proper access controls.

“While there are currently no known pre-authentication remote code execution (RCE) vulnerabilities in MongoDB, and our findings indicate that MongoDB is not being widely exploited at the vulnerability level, the risk remains significant. A single pre-auth RCE zero-day in MongoDB could instantly expose hundreds of thousands of servers and effectively hand attackers a well-oiled ransom machine capable of operating at massive scale.” concludes the report. “For this reason, we strongly recommend applying the prevention and hardening best practices outlined above, as misconfiguration—not exploitation—continues to be the critical enabling factor.”

Pierluigi Paganini



Share This Article

Shocking: Delco Nurse Detained By ICE At LAX During Family Disneyland Trip

PHILADELPHIA — A routine family vacation to Southern California…

China backs Cuba after Trump says island ‘will fall’

Beijing has vowed to support Havana against external interference…

Congressman Scott Perry Exposes Major Washington Overreach During Live TeleTown Hall

Rep. Scott Perry (R-PA) recently connected with constituents across…

Canada MAID Program: Truth About the 16,000 Assisted Deaths

A striking narrative has taken center stage in global…

Dr. Joyce Demands Major Crackdown on Foreign Robocalls Targeting Americans

WASHINGTON — In an era defined by constant connectivity,…

CIA Chief's Moscow Trip Was About Iran, Not A NATO Warning: Estonia's Ex-President

Speculation has abounded over the nature of CIA Director John…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted