TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

RansomEXX Trojan attacks Linux systems

146 pointsby nairboonover 4 years ago

8 comments

Memosyneover 4 years ago
&gt; Each sample of the malware contains a hardcoded name of the victim organization.<p>&gt; Apart from encrypting the files and leaving ransom notes, the sample has none of the additional functionality that other threat actors tend to use in their Trojans: no C&amp;C communication, no termination of running processes, no anti-analysis tricks, etc.<p>&gt; Curiously, the ELF binary contains some debug information, including names of functions, global variables and source code files used by the malware developers.<p>Seems pretty amateurish...
评论 #25029067 未加载
评论 #25028376 未加载
评论 #25033238 未加载
评论 #25030463 未加载
lmilcinover 4 years ago
Rule #1 -- Always be backing up.<p>Rule #2 -- Never download and execute binaries from the Internet if you can&#x27;t track it to reputable source. Linux will not help if you execute it.<p>Rule #3 -- If you can&#x27;t track it but need to run anyway, jail the heck out of it. Create a VM and run it inside, disabling also its ability to use network for anything else than reaching the Internet. Make sure it can&#x27;t reach any other machine in your network or ports on your PC through loopback.
corditeover 4 years ago
Mbedtls is small code size configurable build library. I am not surprised they’re using it, it embeds with applications or firmwares easily and has a decent API. Which cannot be said for openssl.
Animatsover 4 years ago
Are Ubuntu repositories being scanned for this sort of thing?
nitrogenover 4 years ago
How is it distributed to targets? This wasn&#x27;t mentioned in the link.
评论 #25028596 未加载
ktpsnsover 4 years ago
As somebody who has switched to Linux-only (desktop+servers) years ago, seeing how ransomeware gets &quot;ported&quot; to Linux makes me overthinking my backup system.<p>Has anybody experience with immutable backups? This is so important, because many ransomeware codes attacks backups first.<p>I think offline backups on write-once media are the safest. A DVD-RW is the only thing I can think of, but this is quite elaborate and doesn&#x27;t seem contemprary in 2020. Do I miss something?
评论 #25033537 未加载
评论 #25039575 未加载
评论 #25047239 未加载
评论 #25034079 未加载
评论 #25032816 未加载
评论 #25033037 未加载
mootzvilleover 4 years ago
I only have one thing to say...SELinux
评论 #25031214 未加载
spicyramenover 4 years ago
Can this impact EC2?
评论 #25028345 未加载
评论 #25028378 未加载