Data Security, Patch/Configuration Management

Automated extortion attacks target exposed MongoDB instances

Threat actors are actively targeting unsecured MongoDB databases in automated data extortion attacks, demanding low ransoms from owners to restore their compromised data, with further coverage provided by Bleeping Computer.

The attacks exploit misconfigured MongoDB instances accessible without restriction. Researchers from Flare discovered over 208,500 publicly exposed MongoDB servers, with nearly half of those lacking authentication already compromised. The attacker wipes the data and leaves a ransom note, typically demanding 0.005 Bitcoin (approximately $500-$600) within 48 hours for data restoration. Analysis indicates a single threat actor is responsible, using a prevalent Bitcoin wallet address across most ransom notes. Many remaining exposed instances may have already paid a ransom. Additionally, a significant number of exposed servers run older, vulnerable versions, though these are primarily susceptible to denial-of-service attacks rather than remote code execution.

These attacks highlight the critical need for robust database security practices, including avoiding public exposure unless necessary, implementing strong authentication, and enforcing strict network access controls. Regular updates to MongoDB and continuous monitoring for exposure are essential. The lack of guaranteed data recovery after payment underscores the risks associated with these extortion schemes, emphasizing the importance of proactive security measures to prevent such incidents.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds