Threat reportRansomwareTL-2026-0006

Automated MongoDB Extortion Campaign Targeting Exposed Instances

highACTIVE

Automated MongoDB Extortion Campaign Targeting Exposed (TL-2026-0006), also tracked as MongoDB Ransom, is a high-severity ransomware operation scored CVSS 7.5, first published 2026-02-02. It has no confirmed attribution, affects MongoDB MongoDB Server, maps to 23 MITRE ATT&CK techniques (T1005, T1020, T1041), and is covered by 23 detection rules and 70 indicators of compromise.

CVSS
7.5/10High
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
0Not attributed
Detection rules
23SPL · KQL · Sigma
IOCs
70Indicators of compromise

Key facts for TL-2026-0006

Threat ID
TL-2026-0006
Also known as
MongoDB Ransom, Meow Attack, Unistellar Attacks
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
Technology, Healthcare, Education, Government, Financial Services, All Sectors
Target regions
Global
Detection rules
23
Indicators of compromise
70

Malware and tooling in Automated MongoDB Extortion Campaign Targeting Exposed

Malware and tooling: 'meow' string replacing database contents, Database contents replaced with 'meow' string, Database contents replaced with 'meow' string — no ransom note

How Automated MongoDB Extortion Campaign Targeting Exposed works

Automated MongoDB extortion campaigns continue to exploit internet-facing MongoDB instances with default configurations (no authentication, bound to 0.0.0.0). As of February 2026, Shodan identifies 108,826+ MongoDB instances exposed to the internet, with the majority running on default port 27017. A single dominant threat actor ('crazzynoob') accounts for approximately 98% of all MongoDB extortion attacks, operating an industrialized pipeline: automated scanning for open instances → connection without authentication → data exfiltration → database deletion → insertion of ransom note collection demanding $500 in Bitcoin → move to next target. The campaign has compromised an estimated 1,400+ databases across approximately 3,100 unauthenticated instances from a total exposed surface of 208,000+ historically tracked instances. The attack requires ZERO exploits — MongoDB's default configuration prior to version 3.6 ships without authentication enabled, and many operators still deploy without enabling auth even on modern versions. The ransom payment rate is estimated at <5%, but at $500 per demand across 1,400+ targets, even minimal payment rates generate significant revenue. The campaign is FULLY AUTOMATED, targeting exposed instances globally with no sector or geographic preference — any MongoDB instance without authentication is a target regardless of what data it contains.

The MongoDB extortion campaign represents the most fundamental database security failure: production databases exposed to the internet without authentication. This is not a vulnerability exploitation — it is the absence of the most basic security control.

**The Attack Pipeline:**

1. **Scanning**: Automated tools scan internet-facing IP ranges on port 27017 (MongoDB default) and port 28017 (MongoDB HTTP interface). Shodan, Censys, and custom scanners identify targets. As of Feb 2026, Shodan shows 108,826+ exposed instances globally, with China (22,655), US (17,576), Germany (12,351), Hong Kong (6,640), and France (5,302) as the top exposed countries.

2. **Connection**: Attacker connects to exposed MongoDB instance without any credentials. No exploit needed — the instance has no authentication configured. The `mongo` shell or `pymongo` library connects directly.

3. **Exfiltration**: Before deletion, the attacker dumps the database contents. This data has secondary value: PII for identity theft, credentials for stuffing, business data for competitive intelligence, or bulk sale on darknet markets.

4. **Deletion**: All collections dropped. The database is wiped clean.

5. **Ransom Note**: A new collection (typically 'README' or 'WARNING') is inserted containing a ransom demand: send $500 in Bitcoin to a specified wallet address, email proof of payment to receive a data dump. The note threatens permanent deletion if payment is not received within 48 hours.

6. **Automation**: The entire pipeline is automated. The dominant actor 'crazzynoob' operates scripts that process hundreds of instances per day. No human interaction required after initial script deployment.

**The Dominant Actor — 'crazzynoob':**

Flare research and community analysis identified that approximately 98% of MongoDB extortion attacks originate from a single actor using the moniker 'crazzynoob'. Characteristics: - Uses a small number of Bitcoin wallet addresses for ransom collection - Consistent ransom amount ($500 USD equivalent in BTC) - Identical ransom note template across all targets - Automated scanning and exploitation pipeline - No evidence of targeted selection — pure opportunistic automated scanning - Active since at least 2017, with periodic campaign waves - Payment rate estimated <5% — most victims either restore from backup or accept data loss - Despite low payment rate, the campaign persists because automation makes per-target cost near zero

**Exposed Instance Landscape (Feb 2026):**

- **Total exposed (Shodan)**: 108,826+ MongoDB instances - **Default port 27017**: 98,919 (91%) - **Top hosting providers**: Aliyun/Alibaba Cloud (8,876), Hetzner (7,074), DigitalOcean (6,699), Google Cloud (4,072), Contabo (3,822) - **Geographic distribution**: China 22,655, US 17,576, Germany 12,351, Hong Kong 6,640, France 5,302 - **Unauthenticated subset**: Estimated 3,100+ instances with no authentication (down from historical peaks due to MongoDB 3.6+ defaults) - **Growth trend**: Despite improved defaults in MongoDB 4.x+, new deployments on cloud VPS continue to appear without authentication — developer convenience overrides security

**Why This Persists:**

1. **Default configuration gap**: MongoDB pre-3.6 shipped bound to 0.0.0.0 without authentication. Many legacy deployments persist. 2. **Cloud deployment pattern**: Developers spin up VPS instances, install MongoDB for quick prototyping, and never enable auth. The instance stays running indefinitely. 3. **Docker misconfigurations**: MongoDB containers often expose port 27017 to 0.0.0.0 via Docker port mapping without adding authentication. 4. **No immediate consequence**: An exposed MongoDB works perfectly for the developer — the security gap is invisible until the extortion hits. 5. **Automation economics**: The attacker's cost per target approaches zero. Even 1-2% payment rate is profitable.

**Data at Risk:**

Exposed MongoDB instances contain every type of data: - Customer PII (names, emails, addresses, phone numbers) - Application credentials and API keys - Health records (HIPAA violations) - Financial data (PCI violations) - IoT sensor data and industrial telemetry - User session tokens and authentication data - Business intelligence and analytics - Machine learning training datasets

**Connection to Broader Threat Landscape:**

MongoDB extortion is the ENTRY POINT of the data extortion economy: - Stolen data feeds darknet markets (TL-0013 ShinyHunters ecosystem) - Ransom payments flow through crypto laundering (TL-0027 illicit crypto) - Exposed credentials enable credential stuffing (TL-0029 NationStates pattern) - Cloud misconfigurations mirror broader cloud security failures - The same automation pattern applies to other exposed databases (Redis, Elasticsearch, Cassandra, CouchDB)

MITRE ATT&CK techniques used in TL-2026-0006

collection

T1005 Data from Local System; T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories

exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel

discovery

T1046 Network Service Discovery; T1082 System Information Discovery; T1087 Account Discovery

execution

T1059 Command and Scripting Interpreter

defense-evasion

T1078 Valid Accounts

persistence

T1133 External Remote Services

initial-access

T1190 Exploit Public-Facing Application

impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement; T1565 Data Manipulation; T1657 Financial Theft

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

reconnaissance

T1595 Active Scanning; T1596 Search Open Technical Databases

Affected products and versions in Automated MongoDB Extortion Campaign Targeting Exposed

  • MongoDB — MongoDB Server
    Vulnerable versions: All versions when exposed without authentication

Remediation for Automated MongoDB Extortion Campaign Targeting Exposed

Patches

  • [object Object]

Immediate actions

  • Audit all MongoDB instances for internet exposure (port 27017)
  • Enable authentication on ALL MongoDB instances immediately
  • Block port 27017 at perimeter firewall except for required connections
  • Check for ransom note collections (README_TO_RECOVER, WARNING, etc.)
  • Restore from backups if compromised - DO NOT PAY RANSOM

Workarounds

  • Bind MongoDB to localhost only (bindIp: 127.0.0.1)
  • Use SSH tunneling for remote administration
  • Implement IP allowlisting at firewall level

Longer-term hardening

  • Implement network segmentation - databases should never be directly internet accessible
  • Use MongoDB Atlas or VPN for remote access requirements
  • Enable MongoDB audit logging for all operations
  • Implement regular automated backups with offline copies
  • Use TLS encryption for all MongoDB connections
  • Update MongoDB to latest stable version

Weaknesses (CWE) in Automated MongoDB Extortion Campaign Targeting Exposed

CWE-306, CWE-287, CWE-668

Timeline of Automated MongoDB Extortion Campaign Targeting Exposed

  • First major wave of MongoDB extortion attacks reported. Victor Gevers (@0xDUDE) and Niall Merrigan document attacks against exposed instances. Initial campaigns wipe databases and insert ransom notes demanding 0.2 BTC. Thousands of instances compromised within days. MongoDB Security Team issues advisory on enabling authentication.
  • The 'crazzynoob' actor emerges as the dominant MongoDB extortion operator, accounting for approximately 98% of all attacks. Uses standardized $500 BTC ransom demand and identical note templates across all targets. Fully automated scanning and exploitation pipeline processes hundreds of instances daily. Additional actors (harak1r1, 0wn3d) account for remaining 2%.
  • MongoDB 3.6 released with improved security defaults: binds to localhost (127.0.0.1) by default instead of 0.0.0.0. However, many existing deployments remain on older versions, and new deployments often override the default for development convenience. The improved defaults reduce new exposure growth but do not address existing vulnerable instances.
  • Cloud VPS providers (DigitalOcean, Hetzner, AWS, Aliyun) report growing number of MongoDB instances deployed without authentication. Docker and Kubernetes deployments frequently expose port 27017 via port mapping without auth. The cloud development pattern — quick VPS spin-up → MongoDB install → prototype → forget about security — creates a steady stream of new targets despite improved MongoDB defaults.
  • MongoDB extortion campaigns continue at steady pace. Shodan tracks 100,000+ exposed instances globally. 'crazzynoob' remains the dominant actor with consistent $500 ransom. Payment rate estimated <5% but campaign persists due to near-zero per-target cost. Extended campaigns now also target Redis, Elasticsearch, Cassandra, and CouchDB with identical methodology.
  • MongoDB extortion connects to broader threat landscape: stolen data feeds darknet markets (TL-0013), ransom payments flow through crypto laundering (TL-0027), exposed credentials enable credential stuffing (TL-0029), cloud misconfigs mirror broader patterns, and the same automation methodology now targets Redis, Elasticsearch, Cassandra, and CouchDB databases globally.
  • Shodan identifies 108,826+ MongoDB instances exposed to the internet. Top countries: China (22,655), US (17,576), Germany (12,351). Top hosting: Aliyun (8,876), Hetzner (7,074), DigitalOcean (6,699). 91% on default port 27017. Estimated 3,100+ unauthenticated instances remain vulnerable. Campaign active and automated. The fundamental problem — developers deploying databases without authentication on public networks — remains unsolved despite 9+ years of documented extortion.
  • As of 2026-05-29, the automated MongoDB extortion campaign against exposed unauthenticated instances remains ACTIVE, with tracking corpora observing ransom/wipe notes through 13 May 2026, ~1,400+ databases ransacked, and one dominant wallet in ~98% of notes. No takedown, arrest, or actor disruption is reported, and separate MongoDB CVEs (MongoBleed/CVE-2025-14847, CVE-2026-25611) do not supersede this misconfiguration-based threat.

Sources cited for Automated MongoDB Extortion Campaign Targeting Exposed

Detection coverage for TL-2026-0006

As of 2026-02-02, Threadlinqs Intelligence publishes 23 detection rule(s) for TL-2026-0006 across Splunk SPL, Microsoft KQL and Sigma, covering 70 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

23 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
70 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats