Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 17 submissions in the queue.
posted by janrinok on Sunday November 08 2015, @06:12AM   Printer-friendly
from the malware-for-idiots dept.

A new bit of ransomware is now attacking Linux-based machines, specifically the folders associated with serving web pages. Called Linux.Encoder.1 the ransomware will encrypt your MySQL, Apache, and home/root folders. The system then asks for a single bitcoin to decrypt the files.

From Dr.Web Antivirus:

Once launched with administrator privileges, the Trojan dubbed Linux.Encoder.1 downloads files containing cybercriminals’ demands and a file with the path to a public RSA key. After that, the malicious program starts as a daemon and deletes the original files. Subsequently, the RSA key is used to store AES keys which will be employed by the Trojan to encrypt files on the infected computer.


[Ed's Comment: Emphasis mine.]

Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by hemocyanin on Sunday November 08 2015, @10:21AM

    by hemocyanin (186) on Sunday November 08 2015, @10:21AM (#260286) Journal

    One would hope that a server would have a decent backup system in place making this less profitable for the attackers. Grandmas who have all their grandkids photos unbackedup on one computer are a much juicier target.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 3, Funny) by DNied on Sunday November 08 2015, @12:25PM

    by DNied (3409) on Sunday November 08 2015, @12:25PM (#260318)

    Moral of the story: If grandma is root, you'd better get an account on a different machine.

  • (Score: 2) by Bot on Monday November 09 2015, @12:13AM

    by Bot (3902) on Monday November 09 2015, @12:13AM (#260581) Journal

    Deduplicating backup tools like attic might even detect something is wrong when a snapshot swells abruptly.

    --
    Account abandoned.