# MongoDB Data Extortion Campaign - 1,400+ Databases Ransacked

> Automated MongoDB data extortion campaigns have ransacked 1,400+ databases in single waves, operated by competing actor groups (Harak1r1, Kraken0, Cru3lty, Unistellar, m0ng0d4t4b4s3) who run industrialized scan→dump→wipe→ransom pipelines. The operation exploits MongoDB's historical default of binding to 0.0.0.0 with no authentication — a configuration that exposed 68,000+ instances during the 2017 'MongoDB Apocalypse' and continues exposing tens of thousands in 2024-2026. The extortion pipeline is fully automated: Shodan/Masscan enumerate port 27017 → scripts connect without auth → databases are exported (or more commonly, NOT backed up) → all collections are dropped → a single collection 'README' or 'WARNING' is inserted containing a Bitcoin address and ransom demand ($200-$1,000 BTC). The ransom economy is built on a fundamental deception: most attackers do NOT actually copy the victim's data before wiping it. They simply destroy and demand payment for data they never possessed. Analysis of Bitcoin addresses associated with extortion campaigns shows payment rates of 1-5%, generating estimated $100K-$500K per campaign wave across thousands of targets. The operation evolved through distinct phases: Phase 1 (2017 'MongoDB Apocalypse') — Harak1r1 pioneered mass automated extortion, hitting 10,000+ databases in days; Phase 2 (2018-2020) — competitor groups (Cru3lty, Unistellar) entered, overwriting each other's ransom notes; Phase 3 (2020-2022) — 'Meow' attacks emerged, wiping databases without ransom demands (pure destruction); Phase 4 (2023-2026) — evolution to multi-database targeting (MongoDB + Elasticsearch + Redis + Cassandra), increased ransom amounts, and more sophisticated victim selection (targeting databases with valuable data indicators). The 1,400+ databases hit in single campaigns demonstrate the industrial scale: one operator with a single script can extort thousands of victims in hours. The marginal cost per victim is effectively zero — scanning is free, connection requires no credentials, and Bitcoin collection is automated. This is ransomware economics without the ransomware: no encryption, no malware, no exploitation — just connecting to an open door and stealing what's inside.

- **Published:** 2026-02-02T21:25:00Z
- **Last reviewed:** 2026-02-02T21:25:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0023
- **ID:** TL-2026-0023
- **Severity:** HIGH (CVSS 8.6)
- **Category:** EXTORTION
- **Status:** ACTIVE
- **Detections:** 13 · **IOCs:** 47 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The MongoDB extortion ecosystem represents the most efficient cybercrime operation per unit of effort in history. Unlike ransomware (which requires malware development, delivery mechanisms, encryption, and decryption infrastructure), MongoDB extortion requires only: (1) a Shodan API key or Masscan installation, (2) a MongoDB client (mongosh/mongo), (3) a Bitcoin wallet, and (4) a simple script.

The automated extortion pipeline:

STEP 1 — DISCOVERY: Attackers enumerate internet-facing MongoDB instances on port 27017 using Shodan, Censys, or Masscan. Shodan query: 'product:MongoDB port:27017' returns tens of thousands of results. Each result includes IP, port, version, and sometimes database names — enough to assess target value before connecting.

STEP 2 — RECONNAISSANCE: The script connects to each target without authentication (MongoDB's pre-4.0 default bound to 0.0.0.0 with no auth). The attacker runs 'show dbs' to enumerate databases, 'db.stats()' to assess size, and collection names to gauge value (databases named 'production', 'customers', 'orders', 'users' are high-value targets).

STEP 3 — EXFILTRATION (OR NOT): Here lies the fundamental deception. SOME operators export the data via mongodump before wiping (enabling actual data return on ransom payment). MOST operators skip this step entirely — the data volume is too large to store economically, and storing victim data creates legal risk. They simply proceed to deletion.

STEP 4 — DESTRUCTION: The script drops all user-created databases and collections. This takes seconds via 'db.dropDatabase()' for each database. Years of data destroyed in a single API call.

STEP 5 — RANSOM NOTE: A new database (often named 'README', 'WARNING', 'PLEASE_READ', 'RECOVER_YOUR_DATA') is created containing a single document with: a Bitcoin address, a ransom amount ($200-$1,000 in BTC), an email address for 'negotiation', and a deadline (typically 48 hours). Example note: 'All your data is backed up. You must pay 0.015 BTC to [address] to recover it. Email: [address]. Deadline: 48 hours or data is deleted permanently.'

STEP 6 — COLLECTION: Victims who pay receive nothing (data was never backed up) or receive a partial dump. Bitcoin addresses are monitored for payments. Multiple campaigns use the same addresses, enabling tracking of total revenue.

Actor group profiles:

- HARAK1R1: Pioneer of mass MongoDB extortion (December 2016 - January 2017). First to automate the scan→wipe→ransom pipeline at scale. Hit 10,000+ databases in the initial 'MongoDB Apocalypse'. Demanded 0.2 BTC (~$200 at 2017 prices). Set the template all subsequent actors follow. Bitcoin analysis showed ~$28,000 received from initial campaign.

- KRAKEN0: Active 2017-2019. Targeted both MongoDB and Elasticsearch instances. Known for overwriting competitor ransom notes — would wipe databases already ransomed by Harak1r1 and replace with their own note. Demonstrated the 'overwrite' problem: multiple actors competing for the same victims means data is destroyed multiple times.

- CRU3LTY: Active 2018-2020. Focused on smaller databases with indicators of development/startup environments. Demanded lower ransoms ($150-$300) but at higher volume. Operational pattern: scan during weekends when admin response is slowest.

- UNISTELLAR: Active 2019-2021. Larger-scale operations hitting 12,000+ MongoDB instances in single campaigns. Used automated scripts that connected to Shodan API in real-time, maintaining persistent scanning. More sophisticated victim selection: filtered for databases > 100MB (indicating real data vs test instances).

- M0NG0D4T4B4S3: Active 2022-2026. Latest generation extending attacks to Elasticsearch, Redis, Cassandra, and CouchDB. Multi-database scanning pipeline. Higher ransom demands ($500-$1,000) reflecting cryptocurrency price changes. Uses Tor-based email for communication. Represents the evolution from MongoDB-specific to general exposed-database extortion.

- MEOW ATTACKS (2020-2022): Distinctive variant — databases wiped with 'meow' suffix but NO ransom note left. Pure data destruction without financial motive. Speculation: security vigilantes, competitors eliminating already-ransomed instances, or actors testing destructive capabilities. Hit 4,000+ MongoDB and Elasticsearch instances.

Ransom economics analysis:
- Average demand: $200-$1,000 BTC per database
- Payment rate: 1-5% of victims (estimated from Bitcoin address analysis)
- Revenue per campaign (1,400 targets): $2,800-$70,000 at 1-5% payment rate
- Cost per campaign: Near-zero (Shodan subscription $59/month, MongoDB client free, script development hours)
- ROI: 50x-1,000x+ return on investment
- Victim reality: 90%+ of paying victims never receive their data back
- Total ecosystem revenue (2017-2026): Estimated $5M-$20M across all actor groups

The ransom note deception: Security researchers (including Bob Diachenko, Victor Gevers, and the GDI Foundation) analyzed hundreds of extortion cases and found that the majority of attackers NEVER export victim data. The ransom notes claim 'your data is backed up on our servers' — this is almost always false. Victims who pay are paying for nothing. The operation is extortion based on fear, not actual data possession.

MongoDB's response timeline:
- Pre-2016: MongoDB default config bound to 0.0.0.0 with no authentication. Any internet connection = full admin access.
- MongoDB 2.6 (2014): Added --auth flag but not enabled by default.
- MongoDB 3.6 (2017): Changed default binding to localhost (127.0.0.1) — the most impactful single security change. NEW installations are safe.
- MongoDB 4.0 (2018): Authentication enabled by default in some deployment modes.
- MongoDB 7.0+ (2023): Enhanced security defaults, SCRAM authentication, TLS by default in Atlas.
- Problem: Legacy instances from pre-3.6 era still running with 0.0.0.0 binding. Cloud deployments with misconfigured security groups. Docker deployments exposing port 27017. Every new wave of extortion targets the SAME long-standing misconfiguration — the fix exists but isn't applied.

Why this continues (2024-2026):
1. Legacy instances: Pre-3.6 MongoDB installations still running in production
2. Docker misconfigurations: docker run -p 27017:27017 mongo exposes to 0.0.0.0
3. Cloud security groups: AWS/GCP/Azure VMs with 0.0.0.0/0 on port 27017
4. Development instances promoted to production without hardening
5. Backup negligence: No backups = total data loss when wiped, increasing ransom payment pressure

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1485 Data Destruction
- T1486 Data Encrypted for Impact
- T1595 Active Scanning
- T1596 Search Open Technical Databases
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1213 Data from Information Repositories
- T1119 Automated Collection
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft
- T1490 Inhibit System Recovery
- T1046 Network Service Discovery
- T1212 Exploitation for Credential Access
- T1070 Indicator Removal
- T1583 Acquire Infrastructure
- T1098 Account Manipulation
- T1590 Gather Victim Network Information
- T1588 Obtain Capabilities
- T1133 External Remote Services
- T1082 System Information Discovery
- T1087 Account Discovery
- T1074 Data Staged
- T1041 Exfiltration Over C2 Channel
- T1020 Automated Exfiltration
- T1491 Defacement
- T1136 Create Account

## Sources

- [BleepingComputer — MongoDB Apocalypse (2017)](https://www.bleepingcomputer.com/news/security/mongodb-apocalypse-is-here-as-ransom-attacks-hit-10-000-servers/)
- [KrebsOnSecurity — MongoDB Ransom Attacks](https://krebsonsecurity.com/2017/01/mongodb-ransom-attacks/)
- [GDI Foundation — MongoDB Tracking](https://www.gdifoundation.org/)
- [MongoDB Documentation — Security Checklist](https://www.mongodb.com/docs/manual/administration/security-checklist/)
- [MongoDB 3.6 Release Notes — localhost Default](https://www.mongodb.com/docs/manual/release-notes/3.6/)
- [Shodan — MongoDB Exposure](https://www.shodan.io/search?query=product%3AMongoDB)
- [Docker Hub — Official MongoDB Image](https://hub.docker.com/_/mongo)
- [CIS Benchmark — MongoDB](https://www.cisecurity.org/benchmark/mongodb)
- [Bitcoin Abuse Database](https://www.bitcoinabuse.com/)
- [NIST — CWE-306](https://cwe.mitre.org/data/definitions/306.html)
- [NIST — CWE-1188](https://cwe.mitre.org/data/definitions/1188.html)
- [Comparitech — MongoDB Ransomware Research](https://www.comparitech.com/)
- [SecurityDiscovery — Bob Diachenko Exposure Research](https://securitydiscovery.com/)
- [Trend Micro — Database Extortion Analysis](https://www.trendmicro.com/)
- [Elastic — Elasticsearch Security Defaults (8.0)](https://www.elastic.co/blog/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0023
