twr avatar

Hackers Attack IPMI Default Passwords to Deploy Ransomware On Linux Servers

twr

Published: 29 Dec 2018 › Updated: 29 Dec 2018Hackers Attack IPMI Default Passwords to Deploy Ransomware On Linux Servers

Hackers Attack IPMI Default Passwords to Deploy Ransomware On Linux Servers


BleepingComputer recently exposed a Ransomware variant called JungleSec which affects Linux servers through the IPMI (Intelligent Platform Management Interface). The threat actors targeted unsecured IPMIs to remotely access and operate the victim’s system

The Attack


The threat actors first locate systems without secure IPMIs and then gain access through the default password. Hackers can then control and operate the computer. Next, they reboot the system into a single-user mode. Finally, the files are encrypted and the user is directed towards a file named ENCRYPTED.md, which is a demand note.

This note demands 0.3 Bitcoin from the affected system owners, in order to decrypt the data. The demand note warns the computer owners against using Brute Force or other methods to regain access. In fact, the message goes on to state that any change in the bytes indicating such attempts, would result in the permanent loss of the encrypted data.

According to reports, certain victims made the Bitcoin payment, but did not receive any decryption key.

The Solution


The IPMI Remote Console is a standard interface that permits authorised access to the system’s hardware. This tool is extremely useful to operate a server remotely.

However, JungleSec is only a concern for those using the IPMI default password. The best prevention against the JungleSec Ransomware attack is to simply reset your IPMI password to a something more secure, alternatively consider disabling/restricting if not required.


Posted from my blog with SteemPress : https://latesthackingnews.com/2018/12/29/hackers-attack-ipmi-default-passwords-to-deploy-ransomware-on-linux-servers/

Leave Hackers Attack IPMI Default Passwords to Deploy Ransomware On Linux Servers to:

Written by

Read more #bleepingcomputeripmiransomware posts


Best Posts From twr

We have not curated any of twr's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.

More Posts From twr