violetzs
By:
violetzs

My MongoDB has been extorted by a kraken ransomware virus

January 8, 2017 6.9k views
MongoDB CentOS

Hello,

Yesterday my database (MongoDB) had been deleted with a message:

{
"_id" : ObjectId("5871ed160c474c47dc9f3e80"),
"Info" : "Your DB is Backed up at our servers, to restore send 0.1 BTC to the Bitcoin Address then send an email with your server ip",
"Bitcoin Address" : "1J5ADzFv1gx3fsUPUY1AWktuJ6DF9P6hiF",
"Email" : "kraken0@india.com"
}

And this morning, my restored database has been deleted one again. What can I do now? Please give some advice for this case.

Thanks!

9 Answers

They are able to access your MongoDB because it is exposed to the internet, ie anyone can access it. I assume that you don't have a firewall in place to block these connections, if so then you'll need to remedy this else it'll continue to happen.

Mongo has some information on how to do this.

Same thing has happened to my system here. Let me know if you find any valuable solutions, and I'll do same if I do, although the scum who did the hacking might be looking at conversation. Unlikely but possible.

  • I am trying Linuxydave's link. I also want to block "drop" permission from MongoDB. Building backup/restore daily.

I have the same problem.

I pay 2 days ago, but they don't answer anymore. So don't waste your money!

  • We are running Beta so that DB is not important, but we'll be faced this in the future. So we need to take actions from now.

  • Sorry to hear that, but totally expected with these kinds of people and schemes.

I use RoboMongo app on Mac to login with SSH permission to manage databases. This is only way my login information was stolen.

Anyone else?

  • That is your security problem. You have to add auth to your mongodb. That happens to us too :(, we lost 4 days of information, last backup was on January 2nd. And at the same time we lost 100 USD paying for something that dosn't exist, they don't have a backup of your database.

    We learned a important lesson for 100 USD, thats the only positive thing.

    • That's my security problem for sure. just trying to know how they can do that. I'm newbie in MongoDB. So please share anything that helpful to me :)

Had the same issue. SSH'd into the server and noticed a folder called dump was created in the home folder. I was able to restore it and setup authentication. Might help someone else

Hello ,

I have also this problem on my server. and i have no backup from my server. any one please give me solution for backup my data from server.

Thanks in advance.

Hello! I had the same problem on my server. The hole in sequrity is open connection to MongoDB. I wrote a short article how to protect your server http://blondiecode-lh.tumblr.com/post/155621499716/mongodb-extorted-by-a-kraken-ransomware-virus. Hope will be helpful!

Today I tried to connect to our MongoServer from another server, but it does not work. So I wonder how the virus does and is it running on our side server?

It does not stop deleting our database ;'(

Okay, I found the attacker's IP is 46.166.173.106 and make changes in iptables: /etc/sysconfig/iptables

-A INPUT -s 46.166.173.106 -p tcp --dport 27017 -j DROP
-A INPUT -s 46.166.173.106 -p tcp --dport 80 -j DROP
-A INPUT -s 46.166.173.106 -p tcp --dport 22 -j DROP

-A INPUT -s 127.0.0.1 -p tcp --dport 27017 -j ACCEPT
-A INPUT -p tcp --dport 27017 -j DROP

Hope it works to me and stop deleting the databases.

Have another answer? Share your knowledge.