Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

30 Minute Watch Karl Biron,
Senior Security Researcher, LevelBlue

Six years and counting: more than 25,000 unsecured databases worldwide have fallen victim to the Meow cyber-attacks. No ransom, no exfiltration. Just every index overwritten with a random string ending in "-MEOW." Compromised instances are still turning up on Shodan today.

Behaving more like a wiper malware than ransomware, MEOW mapped to MITRE ATT&CK's Data Destruction technique (T1485). No intrusion chain. Just an internet-facing database with no authentication or with weak credentials.

Join our technical cyber lab as SpiderLabs Researcher Karl Biron runs MAD-CAT (Meow Attack Data Corruption Automation Tool), his working, open-source attack tool that reconstructs that methodology across the same six platforms: MongoDB, Elasticsearch, Cassandra, Redis, CouchDB, and Hadoop HDFS, against a simulated multi-database enterprise stack.

This session covers:

  • A full vulnerable database stack via Docker Compose

  • Single-target and bulk CSV-based coordinated execution

  • MAD-CAT's factory pattern architecture for adding new target

Watch the Webinar

Related Resources

Current: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Resource: resourceswebinarsus-water-utility-cyberattacks-what-the-exposure-data-reveals
Webinar

US Water Utility Cyberattacks:​ What the Exposure Data Reveals

Current: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Resource: resourceswebinarsinside-1500-incidents-when-trusted-tools-become-attack-vectors
Webinar

Inside 1,500+ Incidents: When Trusted Tools Become Attack Vectors

Current: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Resource: resourceswebinarsttp-emea-briefing-q2-2026
Webinar

LevelBlue EMEA TTP Briefing Q2 2026