'Malwareless' ransomware campaign operators pwned 83k victims' MySQL servers, 250k databases up for sale

$500 a pop, $25k 'earned' and not much of a trace left, says Guardicore

A “malwareless” ransomware campaign delivered from UK IP addresses targeting weak security controls around internet-facing SQL servers successfully pwned 83,000 victims, according to Israeli infosec biz Guardicore.

“The attack chain is extremely simple and exploits weak credentials on internet-facing MySQL servers” said Guardicore’s Ophir Harpaz in a technical advisory today, estimating that there around five million MySQL servers accessible from the public internet.

Once the database servers are compromised, the miscreants operating the campaign begin a so-called “double extortion” attack, threatening to publish data exfiltrated from the SQL silos unless victims pay a ransom, which also apparently will lead to the restoration of that data.

Holding people's files and records to ransom has become synonymous with application-level malware infections. What we have here is a reminder that crooks can scramble information from afar without having to run bad apps on employees' workstations or host servers.

Beginning in January, Guardicore observed the crime spree evolve over the course of the year through two different strains. “In the first, which lasted from January till the end of November, the attackers left a ransom note with their [Bitcoin] wallet address, the amount of Bitcoin to pay and an email address for technical support,” wrote Harpaz, who said victims were typically given 10 days to stump up.


Forget Snow Day: Baltimore's 115,000+ public school kids get Ransomware Day, must check Win PCs for infection


Typical ransoms were around 0.03 Bitcoins, or about $500 at the time of writing.

Around 1.2 Bitcoins (~$25,000) was deposited to wallet addresses mentioned in ransom notes seen by Guardicore’s researchers, with a total of 250,000 breached databases being offered for sale. Over time the campaign stepped up, sharply increasing in October with the apparent release of a second version.

“The [extortionists'] website is a good example of a double extortion mechanism – it contains all leaked databases for which ransom was not paid. The website lists 250k different databases from 83k MySQL servers, with 7TB of stolen data. Up till now, [Guardicore’s sensor network] captured 29 incidents of this variant, originating from 7 different IP addresses,” added Harpaz.

Version 2’s ransom note, planted inside compromised databases in an unscrambled column, read:

INSERT INTO `WARNING` (`id`, `warning`, `website`, `token`) VALUES (1, ‘To recover your lost databases and avoid leaking it: visit http[.]//hn4wg4o6s5nc7763.onion and enter your unique token ffc7e276a3c7ef27 and pay the required amount of Bitcoin to get it back. Databases that we have: . Your databases are downloaded and backed up on our servers. If we dont receive your payment in the next 9 Days, we will sell your database to the highest bidder or use them otherwise. To access this site you have use the tor browser https://www.torproject.org/projects/torbrowser.html’, ‘http://hn4wg4o6s5nc7763.onion’, ‘ffc7e276a3c7ef27’);

Hailing the attack’s simplicity and the fact that it is seemingly automated and transient, Harpaz concluded: “There are no binary payloads involved in the attack chain, making the attack ‘malwareless’. Only a simple script which breaks in the database, steals information, and leaves a message.”

Internet-facing MySQL databases used by Wordpress are pretty common. Contained in those databases are username and login information for the site they power, which could prove troublesome if users – not just site admins but also article authors and comment posters – recycle their credential pairs elsewhere.

“Double extortion” was last in the news when footie super-club Manchester United was struck by ransomware last month. The technique isn’t new but the handy name for it is relatively so. ®

Similar topics

Other stories you might like

  • IPSE: More than a third of freelancers have quit contracting since IR35 reforms

    Exodus, movement of the people... to the Middle East or elsewhere

    More than a third (35 per cent) of contractors in the UK have become permanent employees, retired, shifted to work overseas or are "simply not working" since IR35 tax legislation was revised earlier this year.

    This is according to the Association of Independent Professionals (IPSE) which found 35 per cent fewer freelancers among those it surveyed since 6 April when the government pushed through the delayed reform.

    "This research shows the devastating impact the changes to IR35 have had on contractors, needlessly compounding the financial damage of the pandemic," said Andy Chamberlain, director of policy at IPSE. "Now, just when contractors are needed the most - amid mounting labour shortages across the UK and particularly in haulage - government decisions have drive out a third of the sector."

    Continue reading
  • New Relic guzzles down CodeStream to help devs jump straight from app error telemetry to offending code

    'I can debug production from the IDE,' said CS boss Peter Pezaris

    Observability company New Relic has acquired CodeStream, specialists in developer collaboration, with the aim being to connect observability data with code in the development environment.

    CodeStream, founded in 2017 by Peter Pezaris, adds instant developer communication to coding environments. For example, a developer puzzling over some code written by a colleague can click next to that code, type a message to the other dev, and they will receive it either in the IDE if they happen to be working on the same project, or in a messaging tool such as Slack, complete with a reference to the code in question. They reply, and a discussion begins.

    Although it may seem a small thing, given that they could just use Slack (or any number of other messaging services) directly, the context and convenience makes it a worthwhile collaboration tool. CodeStream also integrates with pull requests from GitHub, GitLab, BitBucket, and issue management from Jira, Trello and others.

    Continue reading
  • Analogue tones of a ZX Spectrum Load set to ride again via podcast project

    Remember the R Tape Loading Error?

    The glory days of audio-cassette loading are set to return in the coming weeks, with retro fans to be treated to a broadcast for them to hit Play and Record to.

    Audio cassettes were the medium of choice for software back when Sinclair and Commodore's 8-bit hardware ruled the roost. The floppy disk seemed impossibly glamorous for the average home computer user and code was instead delivered via audio.

    While the sound of those files was unintelligible for most, for some enthusiasts it was possible to discern the type of data being loaded. Right up until the all-too-common R Tape Loading Error (which usually seemed to come right at the end of a lengthy period staring at a loading screen).

    Continue reading

Biting the hand that feeds IT © 1998–2021