The newly emerged ransomware actively targets both Windows and Linux systems with a double-extortion approach. . Arika ransomware has continued to evolve since emerging as a threat in March, expanding its reach from initially targeting Windows systems to include Linux servers and employing a growing array of tactics, techniques, and procedures (TTPs). An in-depth report on Akira from LogPoint breaks down the "highly sophisticated" ransomware, which encrypts victim files, deletes shadow copies, and demands ransom payment for data recovery. The infection chain actively targets Cisco ASA VPNs lacking multifactor authentication to exploit the CVE-2023-20269 vulnerability as an entry point. As of early September, the group had successfully hit 110 victims, focusing on targets in the US and the UK. . Arika ransomware relentlessly assaults Linux environments, employing innovative strategies in its dual-extortion tactics; explore its techniques and consequences.. Arika Ransomware, Linux Malware, Cyber Threats, Double Extortion. . LinuxSecurity.com Team
Cyble Research and Intelligence Labs (CRIL) discovered a new ransomware group called Money Message. Both Windows and Linux operating systems are targeted by this ransomware, which can encrypt network shares. Experts believe that threat actors may use stealer logs in their operations. . More than five victims publicly identified as having been impacted by Money Message, the majority of whom are Americans, have already been reported since it was first noticed in March 2023. Industries represented by the victims include BFSI, transportation and logistics, and professional services. The gang targets its victims using a double extortion method that entails exfiltrating the victim’s data before encrypting it. The group posts the data on their leaked website if the ransom is unpaid. The Elliptic Curve Diffie-Hellman (ECDH) key exchange and ChaCha stream cipher algorithm are used by the Money message ransomware to encrypt data on a victim’s Computer and demand a ransom for its release. Researchers stated that , like other ransomware groups, this ransomware does not rename the file after encryption. The link for this article located at Cyber Security News is no longer available. . At least six individuals have been named as having suffered due to Money Message, with most being residents of the United States.. Money Message Ransomware, Data Encryption Threat, Cyber Attack Alerts. . LinuxSecurity.com Team
A novel Linux version of the IceFire ransomware that exploits a vulnerability in IBM's Aspera Faspex file-sharing software has been identified by SentinelLabs, a research division of cybersecurity company Sentinel One. The exploit is for CVE-2022-47986 , a recently patched Aspera Faspex vulnerability. . Known up to now to target only Windows systems, the IceFire malware detected by SentinelLabs uses an iFire extension, consistent with a February report from MalwareHunterTeam — a group of independent cybersecurity researchers analyzing and tracking threats — that IceFire is shifting focus to Linux enterprise systems. Contrary to past behavior targeting technology companies, the Linux variant of IceFire was observed attacking media and entertainment companies. The attackers’ tactics are consistent with those of the "big-game hunting" (BGH) ransomware families, which involve double extortion, attacks against large enterprises, the use of numerous persistence mechanisms, and evasion tactics such as deleting log files, according to the SentinelLabs report . Double extortion occurs when attackers steal data as well encrypting it, and usually ask for ransom that's double the usual payment. . ShadowCrypt malware, originally designed for Windows systems, has now expanded its reach to target Linux servers, posing significant threats to organizations globally.. IceFire Ransomware,Linux Exploit,Cybersecurity Threats,Aspera Faspex,Double Extortion. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.