Thousands of Servers Infected With New Lilocked (Lilu) Ransomware – Slashdot | xxxThousands of Servers Infected With New Lilocked (Lilu) Ransomware – Slashdot – xxx
菜单

Thousands of Servers Infected With New Lilocked (Lilu) Ransomware – Slashdot

八月 5, 2019 - MorningStar

Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 


Forgot your password?
Close

binspamdupenotthebestofftopicslownewsdaystalestupid freshfunnyinsightfulinterestingmaybe offtopicflamebaittrollredundantoverrated insightfulinterestinginformativefunnyunderrated descriptive typodupeerror

Check out Slashdot on LinkedIn & Minds! | Migrate from GitHub to SourceForge quickly and easily with this tool. Check out all of SourceForge’s improvements.

×

115335744 story

Thousands of Servers Infected With New Lilocked (Lilu) Ransomware - Slashdot Thousands of Servers Infected With New Lilocked (Lilu) Ransomware - Slashdot Thousands of Servers Infected With New Lilocked (Lilu) Ransomware - Slashdot Thousands of Servers Infected With New Lilocked (Lilu) Ransomware - Slashdot

Thousands of Servers Infected With New Lilocked (Lilu) Ransomware (zdnet.com) 12

Posted by BeauHD from the shrouded-in-mystery dept.
Longtime Slashdot reader Merovech shares a report from ZDNet: Thousands of web servers have been infected and had their files encrypted by a new strain of ransomware named Lilocked (or Lilu). Infections have been happening since mid-July, and have intensified in the past two weeks, ZDNet has learned. Based on current evidence, the Lilocked ransomware appears to target Linux-based systems only. The way the Lilocked gang breaches servers and encrypts their content is currently unknown. A thread on a Russian-speaking forum puts forward the theory that crooks might be targeting systems running outdated Exim (email) software. It also mentions that the ransomware managed to get root access to servers by unknown means.

Lilocked doesn’t encrypt system files, but only a small subset of file extensions, such as HTML, SHTML, JS, CSS, PHP, INI, and various image file formats. This means infected servers continue to run normally. According to French security researcher Benkow, Lilocked has encrypted more than 6,700 servers, many of which have been indexed and cached in Google search results. However, the number of victims is suspected to be much much higher. Not all Linux systems run web servers, and there are many other infected systems that haven’t been indexed in Google search results. Why it should scare you:
– affects Linux servers
– so far the vector of infection / vulnerability is unknown
– you can craft a Google search to watch it spread!

Thousands of Servers Infected With New Lilocked (Lilu) Ransomware

Comments Filter:

There may be more comments in this discussion. Without JavaScript enabled, you might want to turn on Classic Discussion System in your preferences instead.

Slashdot Top Deals

“In the face of entropy and nothingness, you kind of have to pretend it’s not there if you want to keep writing good code.” — Karl Lehenbauer

Close

Close

Slashdot

Working...


Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51