Threat actors are running large-scale, automated ransomware-style data destruction campaigns against internet-exposed services, prioritizing speed and volume over complex intrusion. One active operation targets publicly accessible MongoDB instances by scanning for unauthenticated databases on 27017, enumerating/exporting contents to gauge value, then dropping collections/databases and inserting ransom notes demanding Bitcoin payments (commonly $500–$600) with short deadlines (often ~48 hours). Reporting cited internet-wide exposure on the order of 200,000 MongoDB servers reachable online, with thousands lacking access controls; analysis of observed compromises suggested a significant portion of fully exposed instances already contain ransom notes, and most payments were linked to a single Bitcoin wallet, indicating a potentially centralized operator.
Separately, a destructive ransomware campaign hit multiple VPS providers by exploiting a critical vulnerability in the Virtualizor management panel ecosystem, including its WHMCS integration/plugin and API communications, enabling attackers to execute unauthorized management-layer commands across nodes/VMs without typical indicators such as anomalous SSH logins. CloudCone confirmed customer disk data on affected nodes was unrecoverable and that it was rebuilding nodes from scratch; HostSlick and OuiHeberg were also named as impacted, with additional providers believed at risk due to shared use of the same management stack. The incidents underscore that exposed admin planes (database services and hosting control panels) can enable rapid, automated destruction and extortion even when traditional host-level access telemetry (e.g., SSH) shows little or no suspicious activity.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Flare researchers reported that the MongoDB extortion activity was still ongoing, though at a smaller scale than the pre-2021 wave, and found that about 45.6% of roughly 3,100 unauthenticated exposed MongoDB servers had already been wiped and left with ransom notes. They also observed over 208,500 publicly exposed MongoDB servers and found wallet reuse patterns indicating one dominant actor behind most attacks.
Threat actors began conducting automated attacks against publicly exposed MongoDB instances that allowed unrestricted access, wiping or deleting data and leaving ransom notes demanding roughly 0.005 BTC within 48 hours. The activity primarily affected servers exposed on port 27017 without authentication and was driven by deployment misconfiguration rather than a MongoDB software flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecyberkendra.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.