Cybereason is now LevelBlue. Proven endpoint protection, now with greater scale and expanded capabilities. Learn More

30 Minute Watch Karl Biron,
Senior Security Researcher, LevelBlue

Six years and counting: more than 25,000 unsecured databases worldwide have fallen victim to the Meow cyber-attacks. No ransom, no exfiltration. Just every index overwritten with a random string ending in "-MEOW." Compromised instances are still turning up on Shodan today.

Behaving more like a wiper malware than ransomware, MEOW mapped to MITRE ATT&CK's Data Destruction technique (T1485). No intrusion chain. Just an internet-facing database with no authentication or with weak credentials.

Join our technical cyber lab as SpiderLabs Researcher Karl Biron runs MAD-CAT (Meow Attack Data Corruption Automation Tool), his working, open-source attack tool that reconstructs that methodology across the same six platforms: MongoDB, Elasticsearch, Cassandra, Redis, CouchDB, and Hadoop HDFS, against a simulated multi-database enterprise stack.

This session covers:

  • A full vulnerable database stack via Docker Compose

  • Single-target and bulk CSV-based coordinated execution

  • MAD-CAT's factory pattern architecture for adding new target

Watch the Webinar

Related Resources

Current: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Resource: resourceswebinars9000-irs-later-the-11-essential-cybersecurity-controls
Webinar

9,000+ IRs Later: The 11 Essential Cybersecurity Controls

Current: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Resource: resourceswebinarsus-water-utility-cyberattacks-what-the-exposure-data-reveals
Webinar

US Water Utility Cyberattacks:​ What the Exposure Data Reveals

Current: resourceswebinarsinside-mad-cat-how-we-recreated-the-meow-attack-for-security-testing
Resource: resourceswebinarsinside-1500-incidents-when-trusted-tools-become-attack-vectors
Webinar

Inside 1,500+ Incidents: When Trusted Tools Become Attack Vectors