HomeSecurityHackers breach databases with legitimate commands

Hackers breach databases with legitimate commands

A new, sophisticated form of ransomware attacks is exploiting legitimate databases to breach organizations worldwide, bypassing traditional security measures through “malware-free operations.”

See also: Critical bugs in Wondershare RepairIt leak user data

databases
Hackers breach databases with legitimate commands

Unlike conventional ransomware that encrypts files using malicious binaries, attackers exploit exposed database services, abusing normal database functionality to steal, delete, and demand ransom for critical data.

The attack methodology represents a significant evolution in cybercriminal tactics, with attackers targeting database servers that are exposed to the Internet and configured with weak passwords or no authentication.

This malicious activity has been observed on multiple database platforms, including MySQL, PostgreSQL, MongoDB, Hadoop, CouchDB , and Elasticsearch. Attackers remotely connect to these servers, copy data to external locations, execute destructive commands to delete databases, and leave ransom notes stored directly in the compromised database structures.

This approach has proven to be highly effective in avoiding detection, as no malicious binary on the target system. The damage is achieved entirely through legitimate database commands, making it difficult for conventional endpoint security solutions to identify the breach.

Ransomware tactics have evolved from isolated incidents to full-scale automated campaigns, with specialized bots constantly scanning the Internet for misconfigured databases. Researchers found that these attacks have increased exponentially since their initial observation in February 2017, when researchers first recorded thousands of open databases being hijacked in mass operations.

See also: DCS: Data breach for vehicle charging service provider

Hackers breach databases with legitimate commands

Today’s attackers operate sophisticated automated systems capable of breaching new exposed targets within hours or minutes of them coming online. The ease of automation and the potential for immediate profit have made malware-free database ransomware a persistent and growing threat to organizations worldwide.

The technical execution of these attacks follows a methodical approach that maximizes both stealth and efficiency. The attackers begin their operations by scanning globally for exposed database ports, specifically targeting port 3306 for MySQL and port 5432 for PostgreSQL.

Once potential targets are identified, they use fingerprinting techniques to confirm that the services are authentic database servers and not honeypots or other deception systems. Authentication bypass represents a critical phase where attackers test for authentication weaknesses, attempt default username and password combinations, and perform brute-force on weak credentials.

After successful authentication, the attack proceeds with data extraction, where attackers sample small chunks of data to evaluate value and confirm database access. The destructive phase uses legitimate SQL commands such as DROP DATABASE to completely delete the database or bulk DELETE to systematically delete data.

In relational databases like PostgreSQL, attackers create new tables with names like RECOVER_YOUR_DATA or README_TO_RECOVER and insert ransom notes as table rows. For NoSQL databases like MongoDB , the process involves creating new collections with suggestive names and inserting ransom notes as documents.

See also: The fallout from the Salesloft AI Chatbot breach continues

Hackers breach databases with legitimate commands

The introduction of the ransom notes usually contains messages like “All your data has been backed up. You must pay 0.043 BTC to recover it. After 48 hours, we will leak and reveal all your data.” These legitimate database operations make detection difficult, as the commands appear as normal administrative activities in monitoring systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS