Over 27,000 MongoDB Databases Held For Ransom Within A Week

The ransomware attacks on poorly secured MongoDB installations have doubled in just a day.

A hacker going by the handle Harak1r1 is accessing, copying and deleting unpatched or badly-configured MongoDB databases and then threatening administrators to ransom in exchange of the lost data.

It all started on Monday when security researcher Victor Gevers identified nearly 200 instances of a

Truffle Hog

Truffle Hog searches through git repositories for high entropy strings, digging deep into commit history and branches. This is effective at finding secrets accidentally committed that contain high entropy.