Ransomware actors behind the attack are currently selling at least compromised 250,000 databases.
PLEASE_READ_ME is the name of the database attackers create on the compromised MySQL server. And since this is an open-source relational database management system, the attack exploits weak credentials, using brute-force, erasing the content from the database, and leaving a brief note instead. The note is placed in a table named “WARNING” and demands up to 0.08BTC to be paid as ransom. The ransom note contains the following message “Your databases are downloaded and backed up on our servers. If we don’t receive your payment in the next 9 days, we will sell your database to the highest bidder or use them otherwise.”
The attack is very simple, using just a script to break into the database. A backdoor is also added for persistence and future access. The bad actors behind this attack managed to successfully attack 85000 servers.
Check the source.
- This Disney Plus Scam Is After Your Bank InfoA newly discovered Disney Plus scam is phishing for your banking information, using an e-mail with a very eye-catching … Read more
- ChatGPT Might Boost Phishing Scams In 2023, Experts WarnWhile AI’s immensely popular ChatGPT is a very useful tool for writers and creators worldwide, it might also help … Read more
- Devastating Ransomware Attack: Oakland Declares State of EmergencyIn the wake of a massive ransomware attack that left the city with no choice but to shut its … Read more
- H0lyGh0st Ransomware After Small and Midsize BusinessesMicrosoft has linked H0lyGh0st, a cyberthreat that emerged in June 2021 and targets small-to-midsized businesses, to North Korean state-sponsored … Read more
- Popular NFT Marketplace Ravaged by $540M Phishing SchemeIn March, a North Korean APT netted $540 million thanks to a massive phishing operation carried out on the … Read more