HomeSecurityNew "Meow" attacks on exposed databases

New “Meow” attacks on exposed databases

Dozens of unsecured databases exposed on the public web are the target of an automated “meow” attack that destroys data without any explanation.

The activity started recently and has attacked Elasticsearch and MongoDB, leaving no explanation or a ransom note.

Searching the IoT search engine Shodan, dozens of databases were identified that have been affected by this attack.

Meow databases

These attacks have pushed researchers into a race to find the exposed databases and report them responsibly before they fall victim to a “Meow” attack.

The most recently publicly known example of a Meow attack is an Elasticsearch database owned by a VPN provider that claimed to keep no logs.

Discovered by researcher Bob Diachenko, the database was initially secure in July, but was breached again five days later.

However, the second time, the owner did not receive any notification. Instead, they "knocked" him out, with almost all records being wiped.

Diachenko told BleepingComputer that there aren't many details about the attacker or the purpose of their actions. He says the attack appears to be an automated script that "overwrites or completely destroys data ."

Researchers first noticed the "meow" attacks on databases a few days ago. They could be the work of someone trying to teach administrators a harsh security lesson by destroying their unsecured data.

Victor Gevers, president of the nonprofit GDI Foundation, has seen this type of attack elsewhere. He says the hacker has also attacked exposed MongoDB databases.

It also saw the first "meow" attacks a few days ago, with a recent one taking place earlier today, just hours after a GDI volunteer responsibly revealed it to the owner.

If there are positive intentions behind these incidents, sometimes nothing good comes of it and valuable data could be lost in the process.

Data leaks from unsecured MongoDB and Elasticsearch databases accessible over the public network are on a downward trend, but there is still some "highly sensitive" information being exposed.

Whoever is behind the “meow” attacks is likely to continue targeting unsecured databases, destroying data. Administrators should make sure they only expose what needs to be exposed and ensure that data is properly secured.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS