LevelBlue Named Premier Remediation Partner for SentinelOne Wayfinder Frontier AI Services. Learn More

30 Minute Watch Karl Biron,
Senior Security Researcher, LevelBlue

Six years and counting: more than 25,000 unsecured databases worldwide have fallen victim to the Meow cyber-attacks. No ransom, no exfiltration. Just every index overwritten with a random string ending in "-MEOW." Compromised instances are still turning up on Shodan today.

Behaving more like a wiper malware than ransomware, MEOW mapped to MITRE ATT&CK's Data Destruction technique (T1485). No intrusion chain. Just an internet-facing database with no authentication or with weak credentials.

Join our technical cyber lab as SpiderLabs Researcher Karl Biron runs MAD-CAT (Meow Attack Data Corruption Automation Tool), his working, open-source attack tool that reconstructs that methodology across the same six platforms: MongoDB, Elasticsearch, Cassandra, Redis, CouchDB, and Hadoop HDFS, against a simulated multi-database enterprise stack.

This session covers:

  • A full vulnerable database stack via Docker Compose

  • Single-target and bulk CSV-based coordinated execution

  • MAD-CAT's factory pattern architecture for adding new target.

Watch the Webinar

Related Resources

Current: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Resource: resourceswebinarsinside-1500-incidents-when-trusted-tools-become-attack-vectors
Webinar

Inside 1,500+ Incidents: When Trusted Tools Become Attack Vectors

Current: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Resource: resourceswebinarsttp-emea-briefing-q2-2026
Webinar

LevelBlue EMEA TTP Briefing Q2 2026

Current: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Resource: resourceswebinarslevelblue-ttp-briefing-q2-2026
Webinar

LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses