Mongo Lock Ransom Attack
Mongo Lock is a new campaign targeting unsecured MongoDB databases for ransom attacks
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Mongo Lock is a new campaign targeting unsecured MongoDB databases for ransom attacks
Threat details
The attackers behind the campaign are scanning the internet for publicly available and unprotected MongoDB databases.
Once connected, the attackers export all reachable databases before deleting them, and will then leave a new database called "Warning" with a collection inside it named "Readme", which contains the ransom note.
Remediation advice
To limit the damage of ransomware and enable recovery:
All critical data must be backed up, and these backups must be sufficiently protected/kept out of reach of ransomware.
Remediation steps
| Type | Step |
|---|---|
Ensure that:
|
Last edited: 14 December 2021 6:00 pm