Live data from Hacker News

Encryption ransomware threatens Linux users

news.drweb.com

1–10 of 29 posts

Re: Encryption ransomware threatens Linux users

#4
No information on how it spreads?

"Once launched with administrator privileges, the Trojan loads into the memory of its process files containing cybercriminals' demands"

This sounds like it needs to run as root, is there any vulnerability involved and do I need to patch things?

Is it just a particularly crazy spam campaign that would somehow trick "website administrators" into running malware as root on their servers?

Re: Encryption ransomware threatens Linux users

#5
post #4

No information on how it spreads? "Once launched with administrator privileges, the Trojan loads into the memory of its process files containing cybercriminals' demands" This sounds like it needs to run as root, is there any vulnerability involved and do I need to patch things? Is it just a particularly crazy spam campaign that would somehow trick "website administrators" into running malware as root on their servers…

I would guess it's privilege escalation (or that it logs in as a user and only affects that user's files)

Re: Encryption ransomware threatens Linux users

#6

Exactly how is this being executed on Linux systems? Dr Web are selling anti-virus. I'd like more info on how it infects systems. Edit: You know, this is really ONLY being reported by Dr Web. Funny that.

There is more technical details at http://vms.drweb.com/virus/?i=7704004&lng=en

Re: Encryption ransomware threatens Linux users

#7
post #4

No information on how it spreads? "Once launched with administrator privileges, the Trojan loads into the memory of its process files containing cybercriminals' demands" This sounds like it needs to run as root, is there any vulnerability involved and do I need to patch things? Is it just a particularly crazy spam campaign that would somehow trick "website administrators" into running malware as root on their servers…

According to Dr. Web, it spreads through USB disks and the internet, and Dr. Web has great solution to that problem:

"Dr.Web Office Control access restriction system: Restricts or completely prohibits access to Internet resources and removable devices, and therefore, excludes the possibility of a virus invading via those sources."

"Users should only have access to the local resources they require to perform their jobs. It's no use trying to convince staff that flash drives are dangerous. It is much easier to centrally disable access to such devices."

Re: Encryption ransomware threatens Linux users

#9

Exactly how is this being executed on Linux systems? Dr Web are selling anti-virus. I'd like more info on how it infects systems. Edit: You know, this is really ONLY being reported by Dr Web. Funny that.

So nice that they fix this issue for all Linux users in the form of a 370 MB binary. Totally not suspicious.
Post reply on HN