Hundreds of Elasticsearch databases targeted in ransom attacks
By Bill Toulas, Bleeping Computer
Hackers have targeted poorly secured Elasticsearch databases and replaced 450 indexes with ransom notes asking for $620 to restore contents, amounting to a total demand of $279,000.
The threat actors set a seven-day deadline for the payments and threaten to double the demand after that. If another week passes without getting paid, they say the victim would lose the indexes.
Those who pay the amount are promised a download link to their database dump that will supposedly help restore the data structure to its original form quickly.
This campaign was discovered by threat analysts at Secureworks, who identified more than 450 individual requests for ransom payment.
According to Secureworks, the threat actors use an automated script to parse unprotected databases, wipe their data, and add the ransom, so there doesn’t appear to be any manual engagement in this operation.
Comments
Post a Comment