All your (data)base are belong to us: Characterizing Database Ransom(ware) Attacks
Kevin van Liebergen, Gibran Gómez, Srdjan Matic, Juan Caballero
Abstract
—We present the first systematic study of database ransom(ware) attacks , a class of attacks where attackers scan for database servers, log in by leveraging the lack of authentication or weak credentials, drop the database contents, and demand a ransom to return the deleted data. We examine 23,736 ransom notes collected from 60,427 compromised database servers over three years, and set up database honeypots to obtain a first-hand view of current attacks. Database ransom(ware) attacks are prevalent with 6K newly infected servers in March 2024, a 60% increase over a year earlier. Our honeypots get infected in 14 hours since they are connected to the Internet. Weak authentication issues are two orders of magnitude more frequent on Elasticsearch servers compared to MySQL servers due to slow adoption of the latest Elasticsearch versions. To analyze who is behind database ransom(ware) attacks we implement a clustering approach that first identifies campaigns using the similarity of the ransom notes text. Then, it determines which campaigns are run by the same group by leveraging indicator reuse and information from the Bitcoin blockchain. For each group, it computes properties such as the number of compromised servers, the lifetime, the revenue, and the indicators used. Our approach identifies that the 60,427 database servers are victims of 91 campaigns run by 32 groups. It uncovers a dominant group responsible for 76% of the infected servers and 90% of the financial impact. We find links between the dominant group, a nation-state, and a previous attack on Git repositories.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8c4b97de-4e23-4fe6-ba5a-6f5699348e88Builds on8
- Tracking Ransomware End-to-endDanny Yuxing Huang, Maxwell Matthaios Aliapoulios, Vector Guo Li, Luca Invernizzi et al.S&P 2018 · 208 citations
- Dial One for Scam: A Large-Scale Analysis of Technical Support ScamsNajmeh Miramirkhani, Oleksii Starov, Nick NikiforakisNDSS 2017 · 116 citations
- Cybercriminal Minds: An investigative study of cryptocurrency abuses in the Dark WebSeunghyeon Lee, Changhoon Yoon, Heedo Kang, Yeonkeun Kim et al.NDSS 2019 · 100 citations
- 6Forest: An Ensemble Learning-based Approach to Target Generation for Internet-wide IPv6 ScanningTao Yang, Zhiping Cai, Bingnan Hou, Tongqing ZhouINFOCOM 2022 · 49 citations
- Watch Your Back: Identifying Cybercrime Financial Relationships in Bitcoin through Back-and-Forth ExplorationGibran Gómez, Pedro Moreno-Sanchez, Juan CaballeroCCS 2022 · 19 citations
Related papers
- An Empirical Study of Data Disruption by Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Yiwen Xu et al.ICSE 2024 · 10 citations
- Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and CoverageGibran Gómez, Kevin van Liebergen, Juan CaballeroCCS 2023 · 10 citations
- Limits of I/O Based Ransomware Detection: An Imitation Based AttackChijin Zhou, Lihua Guo, Yiwei Hou, Zhenya Ma et al.S&P 2023
- Schrödinger's RAT: Profiling the Stakeholders in the Remote Access Trojan EcosystemMohammad Rezaeirad, Brown Farinholt, Hitesh Dharmdasani, Paul Pearce et al.USENIX Security 2018 · 22 citations
- The Ransomware Decade: The Creation of a Fine-Grained Dataset and a Longitudinal StudyArmin Sarabi, Ziyuan Huang, Chenlan Wang, Tai Karir et al.USENIX Security 2025
