Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le juin 19, 2017, 15:00:37

Titre: [Trend]Erebus Resurfaces as Linux Ransomware
Posté par: igor51 le juin 19, 2017, 15:00:37
Erebus Resurfaces as Linux Ransomware

On June 10, South Korean web hosting company NAYANA was hit by Erebus ransomware (detected by Trend Micro as RANSOM_ELFEREBUS.A), infecting 153 Linux servers and over 3,400 business websites the company hosts.


In a notice posted on NAYANA’s website last June 12, the company shared that the attackers demanded an unprecedented ransom of 550 Bitcoins (BTC), or US$1.62 million, in order to decrypt the affected files from all its servers.


Erebus was first seen on September 2016 via malvertisements and reemerged on February 2017 and used a method that bypasses Windows’ User Account Control. Here are some of the notable technical details we’ve uncovered so far about Erebus’ Linux version.


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


Erebus Resurfaces as Linux Ransomware


Source: Erebus Resurfaces as Linux Ransomware (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/1VLqJCEoFGg/)