October 30, 2015 By Shane Schick 2 min read

The MySQL database servers run by countless organizations may soon turn into weapons for launching DDoS attacks if they become infected with the Chikdos malware, security experts warn.

A Trojan first discovered two years ago by Polish cybersecurity officials, Chikdos malware was recently spotted in several countries where cybercriminals were using it for distributed denial-of-service (DDoS) attacks, according to Symantec. The attackers’ technique involves compromising the MySQL database engine’s user-defined function (UDF) capability. Once cybercriminals manage to inject malicious UDF code, they can execute as a library file and turn server bandwidth into a dangerous tool.

Although Chikdos has been used in systems running the open source Linux operating system in the past, iTWire said attackers are focusing on Windows MySQL databases. Most of the incidents tracked so far take place in the Netherlands, India, Brazil and China, but at least one of the DDoS attacks was aimed at a hosting provider based in the U.S.

To some extent, MySQL databases are a natural target for those using the Chikdos malware, suggested SecurityWeek. Available via open source and widely used by many organizations, MySQL has some pre-existing vulnerabilities that may make it easier to pull off DDoS attacks. The campaign appears to be ongoing, though hopefully as news spreads more CISOs and their teams will be able to contain it.

Unlike traditional desktops, MySQL servers have lots of bandwidth, which is one of the key ingredients for anyone interested in launching DDoS attacks, Computerworld pointed out. The best way to avoid becoming a victim is to make sure administrative privileges for all such systems are completely locked down and best practices are followed to avoid SQL injection attacks.

As a starting point, those running MySQL databases should start looking for any signs of the Chikdos malware by checking folders such as \Lib\, \Lib\plugin\ and \Bin\, Softpedia reported. If you see any randomly named .dll files that look at all suspicious, you may have already been compromised by cybercriminals using the Trojan. Unless you act quickly, the next wave of DDoS attacks may not be far behind.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today