# Automated MongoDB Extortion Campaign Targeting Exposed Instances

> Automated MongoDB extortion campaigns continue to exploit internet-facing MongoDB instances with default configurations (no authentication, bound to 0.0.0.0). As of February 2026, Shodan identifies 108,826+ MongoDB instances exposed to the internet, with the majority running on default port 27017. A single dominant threat actor ('crazzynoob') accounts for approximately 98% of all MongoDB extortion attacks, operating an industrialized pipeline: automated scanning for open instances → connection without authentication → data exfiltration → database deletion → insertion of ransom note collection demanding $500 in Bitcoin → move to next target. The campaign has compromised an estimated 1,400+ databases across approximately 3,100 unauthenticated instances from a total exposed surface of 208,000+ historically tracked instances. The attack requires ZERO exploits — MongoDB's default configuration prior to version 3.6 ships without authentication enabled, and many operators still deploy without enabling auth even on modern versions. The ransom payment rate is estimated at <5%, but at $500 per demand across 1,400+ targets, even minimal payment rates generate significant revenue. The campaign is FULLY AUTOMATED, targeting exposed instances globally with no sector or geographic preference — any MongoDB instance without authentication is a target regardless of what data it contains.

- **Published:** 2026-02-02T17:00:00Z
- **Last reviewed:** 2026-02-02T17:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0006
- **ID:** TL-2026-0006
- **Severity:** HIGH (CVSS 7.5)
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Detections:** 23 · **IOCs:** 70 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The MongoDB extortion campaign represents the most fundamental database security failure: production databases exposed to the internet without authentication. This is not a vulnerability exploitation — it is the absence of the most basic security control.

**The Attack Pipeline:**

1. **Scanning**: Automated tools scan internet-facing IP ranges on port 27017 (MongoDB default) and port 28017 (MongoDB HTTP interface). Shodan, Censys, and custom scanners identify targets. As of Feb 2026, Shodan shows 108,826+ exposed instances globally, with China (22,655), US (17,576), Germany (12,351), Hong Kong (6,640), and France (5,302) as the top exposed countries.

2. **Connection**: Attacker connects to exposed MongoDB instance without any credentials. No exploit needed — the instance has no authentication configured. The `mongo` shell or `pymongo` library connects directly.

3. **Exfiltration**: Before deletion, the attacker dumps the database contents. This data has secondary value: PII for identity theft, credentials for stuffing, business data for competitive intelligence, or bulk sale on darknet markets.

4. **Deletion**: All collections dropped. The database is wiped clean.

5. **Ransom Note**: A new collection (typically 'README' or 'WARNING') is inserted containing a ransom demand: send $500 in Bitcoin to a specified wallet address, email proof of payment to receive a data dump. The note threatens permanent deletion if payment is not received within 48 hours.

6. **Automation**: The entire pipeline is automated. The dominant actor 'crazzynoob' operates scripts that process hundreds of instances per day. No human interaction required after initial script deployment.

**The Dominant Actor — 'crazzynoob':**

Flare research and community analysis identified that approximately 98% of MongoDB extortion attacks originate from a single actor using the moniker 'crazzynoob'. Characteristics:
- Uses a small number of Bitcoin wallet addresses for ransom collection
- Consistent ransom amount ($500 USD equivalent in BTC)
- Identical ransom note template across all targets
- Automated scanning and exploitation pipeline
- No evidence of targeted selection — pure opportunistic automated scanning
- Active since at least 2017, with periodic campaign waves
- Payment rate estimated <5% — most victims either restore from backup or accept data loss
- Despite low payment rate, the campaign persists because automation makes per-target cost near zero

**Exposed Instance Landscape (Feb 2026):**

- **Total exposed (Shodan)**: 108,826+ MongoDB instances
- **Default port 27017**: 98,919 (91%)
- **Top hosting providers**: Aliyun/Alibaba Cloud (8,876), Hetzner (7,074), DigitalOcean (6,699), Google Cloud (4,072), Contabo (3,822)
- **Geographic distribution**: China 22,655, US 17,576, Germany 12,351, Hong Kong 6,640, France 5,302
- **Unauthenticated subset**: Estimated 3,100+ instances with no authentication (down from historical peaks due to MongoDB 3.6+ defaults)
- **Growth trend**: Despite improved defaults in MongoDB 4.x+, new deployments on cloud VPS continue to appear without authentication — developer convenience overrides security

**Why This Persists:**

1. **Default configuration gap**: MongoDB pre-3.6 shipped bound to 0.0.0.0 without authentication. Many legacy deployments persist.
2. **Cloud deployment pattern**: Developers spin up VPS instances, install MongoDB for quick prototyping, and never enable auth. The instance stays running indefinitely.
3. **Docker misconfigurations**: MongoDB containers often expose port 27017 to 0.0.0.0 via Docker port mapping without adding authentication.
4. **No immediate consequence**: An exposed MongoDB works perfectly for the developer — the security gap is invisible until the extortion hits.
5. **Automation economics**: The attacker's cost per target approaches zero. Even 1-2% payment rate is profitable.

**Data at Risk:**

Exposed MongoDB instances contain every type of data:
- Customer PII (names, emails, addresses, phone numbers)
- Application credentials and API keys
- Health records (HIPAA violations)
- Financial data (PCI violations)
- IoT sensor data and industrial telemetry
- User session tokens and authentication data
- Business intelligence and analytics
- Machine learning training datasets

**Connection to Broader Threat Landscape:**

MongoDB extortion is the ENTRY POINT of the data extortion economy:
- Stolen data feeds darknet markets (TL-0013 ShinyHunters ecosystem)
- Ransom payments flow through crypto laundering (TL-0027 illicit crypto)
- Exposed credentials enable credential stuffing (TL-0029 NationStates pattern)
- Cloud misconfigurations mirror broader cloud security failures
- The same automation pattern applies to other exposed databases (Redis, Elasticsearch, Cassandra, CouchDB)

## MITRE ATT&CK

- T1595 Active Scanning
- T1596 Search Open Technical Databases
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter
- T1078 Valid Accounts
- T1046 Network Service Discovery
- T1082 System Information Discovery
- T1087 Account Discovery
- T1213 Data from Information Repositories
- T1074 Data Staged
- T1041 Exfiltration Over C2 Channel
- T1020 Automated Exfiltration
- T1485 Data Destruction
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1657 Financial Theft
- T1005 Data from Local System
- T1119 Automated Collection
- T1565 Data Manipulation
- T1491 Defacement

## Sources

- [Shodan — MongoDB Exposure](https://www.shodan.io/search?query=mongodb)
- [MongoDB Security Checklist](https://www.mongodb.com/docs/manual/administration/security-checklist/)
- [CISA](https://www.cisa.gov/)
- [Flare — MongoDB Extortion Analysis](https://flare.io/)
- [GrayhatWarfare — Open Database Discovery](https://grayhatwarfare.com/)
- [NIST SP 800-123 — Server Security](https://csrc.nist.gov/pubs/sp/800/123/final)
- [MongoDB — Enable Authentication](https://www.mongodb.com/docs/manual/tutorial/enable-authentication/)
- [OWASP — Database Security Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Database_Security_Cheat_Sheet.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0006
