Report this

What is the reason for this report?

My MongoDB has been extorted by a kraken ransomware virus

Posted on January 8, 2017

Hello,

Yesterday my database (MongoDB) had been deleted with a message:

{ “_id” : ObjectId(“5871ed160c474c47dc9f3e80”), “Info” : “Your DB is Backed up at our servers, to restore send 0.1 BTC to the Bitcoin Address then send an email with your server ip”, “Bitcoin Address” : “1J5ADzFv1gx3fsUPUY1AWktuJ6DF9P6hiF”, “Email” : “kraken0@india.com” }

And this morning, my restored database has been deleted one again. What can I do now? Please give some advice for this case.

Thanks!



This textbox defaults to using Markdown to format your answer.

You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

I have the same problem.

I pay 2 days ago, but they don’t answer anymore. So don’t waste your money!

I had the same problem because I deployed alpha edition and didn’t care security. I thought no body would know my server but some guy lurked in and asked for some BTC payment. That’s interesting how they knew my server address when it was just created, not in production yet. I ignored the message, set up firewall, limit source ip access, enable MongoDB authentication. So far, the issue hasn’t happened again yet. And one advice for you guys: NEVER PAY MONEY. They don’t care your data, all they want is money. If you pay money, you shot yourself twice.

They are able to access your MongoDB because it is exposed to the internet, ie anyone can access it. I assume that you don’t have a firewall in place to block these connections, if so then you’ll need to remedy this else it’ll continue to happen.

Mongo has some information on how to do this.

The developer cloud

Scale up as you grow — whether you're running one virtual machine or ten thousand.

Get started for free

Sign up and get $200 in credit for your first 60 days with DigitalOcean.*

*This promotional offer applies to new accounts only.