85K MySQL Servers were hit by PLEASE_READ_ME Ransomware

by | December 11, 2020 | Cybersecurity News

Ransomware actors behind the attack are currently selling at least compromised 250,000 databases.

PLEASE_READ_ME is the name of the database attackers create on the compromised MySQL server. And since this is an open-source relational database management system, the attack exploits weak credentials, using brute-force, erasing the content from the database, and leaving a brief note instead. The note is placed in a table named “WARNING” and demands up to 0.08BTC to be paid as ransom. The ransom note contains the following message “Your databases are downloaded and backed up on our servers. If we don’t receive your payment in the next 9 days, we will sell your database to the highest bidder or use them otherwise.”

The attack is very simple, using just a script to break into the database. A backdoor is also added for persistence and future access. The bad actors behind this attack managed to successfully attack 85000 servers.

Check the source.


Read More

    Attribution:

    Photo by Walkator on Unsplash

    by ATTACK Simulator

    April 2021 Release
    April 2021 Release

    Our latest release comes packed with amazing features, like SMiShing simulations, Sender Identity and many more.

    There’s no reason to postpone training your employees

    Get a quote based on your organization’s needs and start building a strong cyber security infrastructure today.