Hackers Attack IPMI Default Passwords to Deploy Ransomware On Linux Servers
BleepingComputer recently exposed a Ransomware variant called JungleSec which affects Linux servers through the IPMI (Intelligent Platform Management Interface). The threat actors targeted unsecured IPMIs to remotely access and operate the victim’s system
The Attack
The threat actors first locate systems without secure IPMIs and then gain access through the default password. Hackers can then control and operate the computer. Next, they reboot the system into a single-user mode. Finally, the files are encrypted and the user is directed towards a file named ENCRYPTED.md, which is a demand note.
This note demands 0.3 Bitcoin from the affected system owners, in order to decrypt the data. The demand note warns the computer owners against using Brute Force or other methods to regain access. In fact, the message goes on to state that any change in the bytes indicating such attempts, would result in the permanent loss of the encrypted data.
According to reports, certain victims made the Bitcoin payment, but did not receive any decryption key.
The Solution
The IPMI Remote Console is a standard interface that permits authorised access to the system’s hardware. This tool is extremely useful to operate a server remotely.
However, JungleSec is only a concern for those using the IPMI default password. The best prevention against the JungleSec Ransomware attack is to simply reset your IPMI password to a something more secure, alternatively consider disabling/restricting if not required.
Posted from my blog with SteemPress : https://latesthackingnews.com/2018/12/29/hackers-attack-ipmi-default-passwords-to-deploy-ransomware-on-linux-servers/
Leave Hackers Attack IPMI Default Passwords to Deploy Ransomware On Linux Servers to:
Read more #bleepingcomputeripmiransomware posts
Best Posts From twr
We have not curated any of twr's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.
More Posts From twr
- Will a VPN Protect Me From a Data Breach?
- Why DDoS Attacks Are Still One of the Biggest Cyberthreats
- Why Do Subdomain Lookups for Cybersecurity?
- What You Need To Know About Bitcoin Before Investing Your Money In It
- Massive Cyberattacks that Shook the World in 2020
- Data of 176 Million Pakistani Citizens Found For Sale On Dark Web
- Apple Patched Three Zero-Days With The Release Of iOS 14.4
- Watch Out For This Wormable Malware Spreading Via WhatsApp
- What Password Managers Are Safe to Use in 2021
- 7 Reasons to Choose an Outsourced Security Services Provider