blog syssoft ramsome ware software attack

Ransomware: Protect Your MySQL DB From GandCrab Cyber attack

Recently the database in the cloud was hacked. Upon investigation found that the database structure changed. New database along with the new table and the attacker created user.
I have captured crime scene pictures and hope this will help you understand better.

blog syssoft mysql ransomeware

Scene One: a new database ‘warning’ is created, along with the new table ‘WARNING’ with a ransom text.

Scene Two: a new user ‘server’ created.

blog syssoft mysql db

Scene Three: Copy DB files to the local PC. And MS window security tools have detected the trojan virus. In the MySQL database.

GandCrab ransomware

This is a specific form of malware whose goal is to encrypt the data on an infected server. This makes the data inaccessible to users and can cripple an organization. The cybercriminals will decrypt the data if their financial demands are met. Paying the ransom may or may not get your data back. Remember, you are dealing with criminals and their word is not to be trusted.

Tricks used by Hackers and How to secure database

Hackers are searching for MySQL logins that are not properly protected. This may be because of a weak password or in some default installation password, no password at all.
Failure to protect your MySQL database may allow hackers to turn it into a launching pad for malware.


Here are a few suggestions for protecting your MySQL Database server from ransomware or any kind of cyber attack

  1. Always use strong passwords.
  2. Drop direct access to your MYSQL servers from the Internet.
  3. Check your MySQL control settings and logs.
  4. Keep Backup of Database.

Join to become subscribers

Stay in the loop with everything you need to know.

Discover more from syssoft

Subscribe now to keep reading and get access to the full archive.

Continue reading