Inside MAD-CAT: How we recreated the Meow attack for security testing

Save My Seat
HubSpot-LP-hero-500x300@2x
Save My Seat
elements

📅 Thursday, August 20, 2026 | 10AM CT | 4PM BST


Technical Cyber Lab

Six years and counting: more than 25,000 unsecured databases worldwide have fallen victim to the Meow cyber-attacks. No ransom, no exfiltration. Just every index overwritten with a random string ending in "-MEOW." Compromised instances are still turning up on Shodan today.

Behaving more like a wiper malware than ransomware, MEOW mapped to MITRE ATT&CK's Data Destruction technique (T1485). No intrusion chain. Just an internet-facing database with no authentication or with weak credentials.

Join our technical cyber lab as SpiderLabs Researcher Karl Biron runs MAD-CAT (Meow Attack Data Corruption Automation Tool), his working, open-source attack tool that reconstructs that methodology across the same six platforms: MongoDB, Elasticsearch, Cassandra, Redis, CouchDB, and Hadoop HDFS, against a simulated multi-database enterprise stack.

What this session covers

  • A full vulnerable database stack via Docker Compose

  • Single-target and bulk CSV-based coordinated execution

  • MAD-CAT's factory pattern architecture for adding new target

 

Speaker

 Karl Biron, Senior Security Researcher, LevelBlue SpiderLabs

 

 

Save My Seat