All your (data)base are belong to us: Characterizing Database Ransom(ware) Attacks

Kevin van Liebergen (the Institute)

Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Ransomware

Overview

In an increasingly digital world, databases serve as the bedrock for countless services, storing critical information that ranges from personal data to operational intelligence. This centrality makes them an irresistible target for malicious actors. Kevin van Liebergen, a researcher from the Institute, presented a groundbreaking talk at the NDSS Symposium titled "All your (data)base are belong to us: Characterizing Database Ransom(ware) Attacks." This presentation unveiled the first systematic study into database ransomware attacks, offering a comprehensive look into their prevalence, operational mechanics, and the underlying vulnerabilities that enable them.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction to database ransomware attacks and study scope
  2. 2:00 Honeypot findings: attack sequence and scam nature
  3. 3:50 Methodology for identifying ransomware campaigns
  4. 4:50 Methodology for identifying ransomware groups
  5. 6:15 Overall findings: groups, losses, and activity
  6. 7:00 Analysis of the dominant database ransomware group
  7. 8:00 Root cause of attacks: weak authentication

All your (data)base are belong to us: Characterizing Database Ransom(ware) Attacks

Speakers: Kevin van Liebergen, the Institute

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=p9p-gU1Bp1M

Overview

In an increasingly digital world, databases serve as the bedrock for countless services, storing critical information that ranges from personal data to operational intelligence. This centrality makes them an irresistible target for malicious actors. Kevin van Liebergen, a researcher from the Institute, presented a groundbreaking talk at the NDSS Symposium titled "All your (data)base are belong to us: Characterizing Database Ransom(ware) Attacks." This presentation unveiled the first systematic study into database ransomware attacks, offering a comprehensive look into their prevalence, operational mechanics, and the underlying vulnerabilities that enable them.

The research sheds light on a pervasive threat where attackers exploit unauthenticated database servers, delete their contents, and leave behind a ransom note within a new table. Van Liebergen meticulously detailed the methodology for identifying and clustering attacker groups, revealing a landscape dominated by highly automated and professional operations. A crucial finding from the study is that, despite the "ransomware" moniker, these attacks typically involve the simple deletion of data without exfiltration, rendering data recovery impossible even if a ransom is paid. The speaker aptly refers to these incidents as "scams," highlighting the deceptive nature of the threat.

The significance of this work extends beyond mere characterization. It provides critical insights for defenders, emphasizing the urgent need for robust authentication practices and the activation of default security features that are often overlooked or intentionally disabled. By quantifying the financial impact—estimated at nearly half a million dollars in victim losses—and identifying the "dominant group" responsible for the vast majority of these attacks, the research underscores the scale and sophistication of this persistent threat. This talk serves as a stark reminder of the fundamental security hygiene required to protect vital data assets in an era of automated exploitation.

Background

▶ Watch: Introduction to database ransomware attacks and study scope (0:00)

The problem addressed by this research stems from the critical role databases play in modern digital infrastructure. As repositories of sensitive and operational data, they represent high-value targets for attackers seeking financial gain or disruption. The specific class of attacks under investigation, termed "database ransomware," follows a consistent pattern: attackers scan the internet for unauthenticated database servers, gain unauthorized access, proceed to delete the existing database content, and then create a new database table containing a ransom note. These notes typically include payment details, such as Bitcoin addresses and demanded amounts, alongside contact information like email or onion addresses, promising data recovery upon payment. This entire sequence is defined by the researchers as an "infection."

Prior to this study, there was a notable absence of systematic research into the landscape and mechanics of database ransomware attacks. To fill this gap, the researchers adopted a dual-pronged methodology. First, they leveraged data from the LeakIX Internet Scanner, a tool designed to scan all IP addresses, identify running services, and collect ransom notes from infected servers. This yielded a substantial dataset of 302,000 infections across 60,000 unique IP addresses, with 23,000 distinct ransom notes collected between 2021 and 2024.

Second, to gather first-hand information and deeply understand the attack process, the team deployed five honeypots in various countries using different cloud hosting providers. These honeypots were configured with an empty password for the root user and populated with artificially generated data to simulate real-world targets. Over a two-month period, these honeypots recorded 151 infections, providing invaluable log data. Analysis of these logs revealed a consistent sequence of automated commands: attackers would brute force logins using common usernames, list available databases, delete the data, and then leave their ransom note. Optionally, some attackers would further secure their "claim" by locking the database, either by turning it off or disabling its internet connections, to prevent other groups from infecting the same server.

A critical initial finding from the honeypot observations was the highly automated nature of these attacks, with the first infection occurring just 14 hours after honeypot deployment. More importantly, the logs showed no evidence of malware installation or data exfiltration. The attackers simply deleted the data. This led the researchers to conclude that even if a victim pays the ransom, data recovery is impossible, as the data is not backed up or held by the attackers. Consequently, the speaker emphasized that these incidents are more accurately described as "scams" rather than traditional ransomware, which typically involves encryption and the potential for decryption keys upon payment.

Key Findings

▶ Watch: Methodology for identifying ransomware campaigns (3:50)

The systematic study uncovered a detailed landscape of database ransomware attacks, identifying distinct attacker groups, their operational patterns, and the significant financial impact they impose. Through a sophisticated clustering methodology, the researchers identified 32 unique attacker groups operating across 91 distinct campaigns, derived from an analysis of 23,000 ransom notes collected from 302,000 infections.

A major revelation was the estimated victim losses, which account for nearly half a million dollars. This figure underscores the substantial financial drain these "scams" inflict on organizations, despite the futility of paying the ransom.

One of the most striking findings was the identification of a "dominant group" that exerts disproportionate influence over the database ransomware landscape. This group has been continuously active since 2017 and is responsible for an astonishing 76% of all server infections observed in the study. Furthermore, it accounts for 90% of the total revenue generated from these attacks. The dominant group exhibits high polymorphism, running 35 different campaigns, and demonstrates a broader targeting scope, attacking databases beyond just MySQL and Elasticsearch, including Oracle and Postgres. Honeypot analysis confirmed the professionalism of this group, showing they find victims faster, infect more servers, utilize dedicated infrastructure, and employ more complex procedures, such as actively locking databases to prevent other attackers from interfering. Disturbingly, the research also linked one Bitcoin address used by this dominant group to a 2019 Git repository attack, and another Bitcoin address was found to have sent funds to an address attributed to North Korea, hinting at potential state-sponsored or organized criminal ties.

Beyond the dominant group, the study revealed other notable characteristics of the attacker ecosystem:

  • Target Diversity: Two of the identified groups attack both MySQL and Elasticsearch servers, indicating a broad targeting strategy. One group uniquely uses ransom notes in both Chinese and English, suggesting a wider international reach or specific targeting.
  • Geographical Focus: Five groups were observed to exclusively target servers located in China, indicating localized or regionally focused operations.
  • Operational Longevity: The persistence of these groups is remarkable, with 14 groups operating for more than one year and four groups active for over four years. A significant 18 groups were found to be active between 2021 and 2024, highlighting the ongoing and evolving nature of this threat.
  • Attack Growth: The problem is escalating rapidly, with a 60% increase in attacks compared to the previous year, signaling a growing threat landscape.

The root cause underlying the prevalence of these attacks was unequivocally identified as weak authentication. A detailed comparison between Elasticsearch and MySQL servers revealed critical insights:

  • Infection Distribution: Two-thirds of all infected servers were Elasticsearch, while the remaining one-third were MySQL. This is particularly significant given that MySQL servers outnumber Elasticsearch servers on the internet by two orders of magnitude.
  • MySQL Vulnerabilities: MySQL implemented an optional security feature in 2010 designed to strengthen authentication post-installation. The study found that 98% of infected MySQL servers were running versions with this security feature available, yet users evidently failed to run it after installation, leaving their systems vulnerable.
  • Elasticsearch Vulnerabilities: Elasticsearch introduced a mandatory security feature in 2022. However, the research showed that 11% of infected Elasticsearch servers were running versions that included this feature, implying that users had actively deactivated it. Furthermore, 89% of infected Elasticsearch servers were running older versions without this mandatory security feature.
  • Conclusion on Weak Authentication: The primary reason for weak authentication in both database types is the slow adoption of updates and, critically, the deactivation or non-execution of available security features by users and administrators. This human factor creates a vast attack surface for automated exploitation.

Technical Deep Dive

▶ Watch: Methodology for identifying ransomware groups (4:50)

The core of this research lies in its robust methodology for systematically identifying and clustering database ransomware campaigns and the groups behind them. This involved a multi-stage process leveraging both large-scale internet scan data and focused honeypot observations.

The process began with campaign identification, aiming to group similar ransom notes that likely originated from the same attacker template. This comprised two key steps:

  1. Normalization: The initial dataset of 23,000 raw ransom notes was subjected to a normalization process. This involved replacing all Indicators of Compromise (IOCs)—specifically Bitcoin addresses, email addresses, and onion addresses—with generic macros (e.g., [BITCOIN_ADDRESS]). This critical step allowed the researchers to abstract away unique payment details and focus on the structural and linguistic similarities of the notes. Normalization reduced the 23,000 raw notes to 14,000 unique normalized ransom notes.
  2. Note Similarity Clustering: Following normalization, the 14,000 normalized notes were further clustered based on textual similarity. This step merged notes that exhibited minor syntactic modifications, such as the addition or removal of spaces or a few words, which are common variations within a single campaign template. This process successfully grouped the 14,000 normalized notes into 91 distinct campaigns.

Once campaigns were identified, the next stage was group identification, which aimed to link multiple campaigns to the same underlying attacker group. This also involved two primary steps:

  1. Indicator of Compromise (IOC) Reuse: The researchers constructed a graph where nodes represented either identified campaigns or specific IOCs (email, Bitcoin, or onion addresses). An edge was drawn between a campaign node and an IOC node if that IOC was present in the campaign's ransom notes. Crucially, if two different campaigns shared the same IOC (e.g., the same Bitcoin address), an implicit link was established, indicating they likely belonged to the same group. This IOC reuse analysis effectively merged related campaigns, reducing the initial 91 campaigns into 33 preliminary groups.
  2. Bitcoin Multi-Input Clustering: To further refine group identification and leverage the transparency of the Bitcoin blockchain, the researchers employed Bitcoin multi-input clustering. This technique identifies instances where multiple Bitcoin addresses contribute funds to a single transaction, suggesting common ownership or control. The Whatserback tool was utilized for this analysis, which not only identifies these multi-input clusters but also provides estimates of the revenue associated with specific Bitcoin addresses. Groups that were found to share Bitcoin addresses within the same multi-input cluster were then merged. This final step consolidated the 33 preliminary groups into 32 definitive attacker groups.

The honeypot deployment provided crucial behavioral insights that complemented the large-scale data analysis. The five honeypots, intentionally left with weak authentication (empty root password) and populated with artificial data, captured 151 infections over two months. The logs from these honeypots revealed the precise command sequences executed by attackers: initial brute-force attempts, followed by commands to list databases, delete their contents, and then create new tables to insert ransom notes. Importantly, the honeypots confirmed the absence of malware installation or data exfiltration, reinforcing the "scam" nature of these attacks. The honeypots also observed attackers employing more sophisticated tactics like "locking" the database by turning it off or disabling network connections, a strategy to prevent other groups from infecting the same victim. These honeypot observations allowed the researchers to link specific honeypot-observed groups (Group A and Group B) to the broader internet-identified groups, with Group A being linked to the dominant group and Group B to a fifth group identified in the clustering. This linkage provided direct behavioral evidence supporting the characteristics attributed to these groups based on their ransom note patterns and IOC usage.

Demo / Proof of Concept

▶ Watch: Analysis of the dominant database ransomware group (7:00)

The talk did not feature a live technical demonstration or a specific proof-of-concept tool being showcased during the presentation. Instead, the researchers' methodology involved deploying and analyzing honeypots to observe real-world database ransomware attacks in action. These honeypots, configured with intentionally weak security (an empty root password) and populated with artificial data, served as a controlled environment to capture the live sequence of commands used by attackers. The insights gained from these honeypot interactions, such as the brute-force attempts, data deletion commands, and the creation of ransom note tables, constituted the practical "proof of concept" of how these attacks unfold in the wild. This observational approach provided concrete evidence of the automated nature of the infections and, critically, confirmed the absence of data exfiltration, solidifying the claim that these are primarily data deletion "scams."

Defensive Implications

▶ Watch: Root cause of attacks: weak authentication (8:00)

The findings from "All your (data)base are belong to us" provide critical, actionable intelligence for organizations to bolster their defenses against database ransomware attacks. Given the automated, widespread nature of these threats and the devastating consequence of irreversible data loss, immediate and proactive measures are paramount.

  1. Prioritize Strong Authentication: The most significant takeaway is that weak authentication is the primary vector for these attacks. Organizations must enforce robust password policies, utilize multi-factor authentication (MFA) wherever possible, and ensure that default or root user accounts are never left with empty or easily guessable passwords. Regular audits of user accounts and permissions are essential.
  2. Enable and Maintain Database Security Features: The study highlighted that even when security features are available, they are often not enabled or are actively deactivated.
  • For MySQL users, it is crucial to execute the mysql_secure_installation script immediately after installation. This script helps set a root password, remove anonymous users, disallow remote root login, and remove test databases.
  • For Elasticsearch deployments, ensure that security features, which became mandatory in versions from 2022 onwards, are not only enabled but actively configured and maintained. If using older versions, prioritize upgrading to secure versions.
  • Avoid deactivating default security settings unless absolutely necessary and with a thorough understanding of the risks.
  1. Implement Robust Backup Strategies: Since the research conclusively demonstrates that data is simply deleted and not exfiltrated or recoverable even if a ransom is paid, comprehensive and regular backups are the only viable recovery strategy. Backups must be:
  • Automated: To ensure consistency and reliability.
  • Offsite/Offline: To protect against simultaneous deletion or compromise of backups.
  • Tested: Regularly verify the integrity and restorability of backups.
  • Versioned: Maintain multiple versions of backups to allow recovery from different points in time.
  1. Do Not Pay the Ransom: The research unequivocally states that paying the ransom is futile. The data is already gone, and attackers do not possess a copy or a means to restore it. Paying only validates the attacker's business model and provides funds for future attacks. Organizations should focus their resources on prevention and recovery through backups.
  2. Educate Users and Administrators: A significant portion of the vulnerability stems from human error—either ignorance of security features or deliberate deactivation. Regular security awareness training for database administrators, developers, and IT staff is crucial. This training should cover:
  • The importance of strong, unique passwords.
  • The proper configuration and maintenance of database security features.
  • The risks associated with exposing unauthenticated databases to the internet.
  • The critical role of backups.
  1. Monitor for Suspicious Activity: Implement logging and monitoring solutions for database access and modification attempts. Look for:
  • Repeated failed login attempts (brute-force attacks).
  • Unauthorized schema changes, such as the creation of new tables with unusual names (e.g., "Read me to recover your data").
  • Sudden deletion of large volumes of data.
  • Attempts to disable database services or network connections from unexpected sources.
  1. Regular Patching and Updates: The slow adoption of security updates was identified as a key factor. Ensure all database software, operating systems, and related components are kept up-to-date with the latest security patches. This minimizes the window of opportunity for attackers exploiting known vulnerabilities.
  2. Network Segmentation and Firewalls: Limit direct exposure of databases to the public internet. Implement network segmentation and configure firewalls to restrict access to database ports (e.g., MySQL's 3306, Elasticsearch's 9200) only from trusted IP addresses or internal networks.

By adopting these defensive postures, organizations can significantly reduce their attack surface and mitigate the severe impact of database ransomware scams.

Key Takeaways

  • Pervasive and Automated Scams: Database "ransomware" attacks are widespread, highly automated, and often operate as scams where data is simply deleted without exfiltration, making recovery impossible even if a ransom is paid.
  • Weak Authentication is the Primary Vulnerability: The root cause of these infections is consistently weak authentication, stemming from neglected security feature activation (MySQL) or intentional deactivation (Elasticsearch), despite available protections.
  • Dominant and Professional Attacker Groups: A "dominant group" is responsible for an overwhelming majority (76% of infections, 90% of revenue) of these attacks, exhibiting high professionalism, polymorphism, and long-term operation, hinting at sophisticated criminal enterprises.
  • Data Deletion, Not Exfiltration: Attackers primarily delete database contents rather than exfiltrating them, emphasizing the critical importance of robust, tested backups as the only viable data recovery strategy.
  • Futility of Paying Ransom: Victims are strongly advised against paying the ransom, as the data is irrecoverable, and payment only incentivizes further malicious activity.
  • Sophisticated Attacker Tracking: The research showcases advanced methodologies, including IOC reuse and Bitcoin multi-input clustering with tools like Whatserback, for identifying and attributing distinct attacker campaigns and groups.

About the Speaker(s)

Kevin van Liebergen is a researcher affiliated with "the Institute." His work, as presented at the NDSS Symposium, focuses on shedding light on critical cybersecurity threats, particularly in the realm of database security and ransomware. His systematic study on characterizing database ransomware attacks represents a significant contribution to understanding the operational landscape and defensive implications of these pervasive digital threats.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent, methodologically sound academic research that fills a genuine gap — the first systematic characterization of database ransomware at scale. The Bitcoin clustering and IOC graph methodology is the interesting part, but the operational findings (weak auth bad, pay no ransom, use backups) are so self-evident they border on padding.

Heather Calloway (CISO) — SOLID

Methodologically rigorous academic research that correctly identifies a widespread, preventable threat — but it stays in researcher mode the whole time. The findings are real, the scam framing is clarifying, and the root cause diagnosis is accurate. What's missing is any treatment of why this keeps happening at institutions that should know better.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025