Hackers of India

MELEE: A Tool to Identify Ransomware Infections in MySQL Deployments

By  Aditya K Sood  on 10 Aug 2023 @ Blackhat : Arsenal

This Tool Demo covers following tools where the speaker has contributed or authored
MELEE

Abstract

Attackers are abusing MySQL instances for conducting nefarious operations on the Internet. The cybercriminals are targeting exposed MySQL instances and triggering infections at scale to exfiltrate data, destruct data, and extort money via ransom. For example one of the significant threats MySQL deployments face is ransomware. We have authored a tool named “MELEE” to detect potential infections in MySQL instances. The tool allows security researchers, penetration testers, and threat intelligence experts to detect compromised and infected MySQL instances running malicious code. The tool also enables you to conduct efficient research in the field of malware targeting cloud databases.