📅 Thursday, August 20, 2026 | 10AM CT | 4PM BST
Technical Cyber Lab
Six years and counting: more than 25,000 unsecured databases worldwide have fallen victim to the Meow cyber-attacks. No ransom, no exfiltration. Just every index overwritten with a random string ending in "-MEOW." Compromised instances are still turning up on Shodan today.
Behaving more like a wiper malware than ransomware, MEOW mapped to MITRE ATT&CK's Data Destruction technique (T1485). No intrusion chain. Just an internet-facing database with no authentication or with weak credentials.
Join our technical cyber lab as SpiderLabs Researcher Karl Biron runs MAD-CAT (Meow Attack Data Corruption Automation Tool), his working, open-source attack tool that reconstructs that methodology across the same six platforms: MongoDB, Elasticsearch, Cassandra, Redis, CouchDB, and Hadoop HDFS, against a simulated multi-database enterprise stack.
What this session covers
-
A full vulnerable database stack via Docker Compose
-
Single-target and bulk CSV-based coordinated execution
-
MAD-CAT's factory pattern architecture for adding new target
Speaker
Karl Biron, Senior Security Researcher, LevelBlue SpiderLabs