Encryption ransomware threatens Linux users
news.drweb.com
news.drweb.com
Why I'm reciting that story is this: It is perfectly fine for a binary to write executable code to other files. Your typical compiler does. The kernel isn't there to prevent that. The kernel is supposed to prevent it if you configure a security policy that forbids it - starting with things as simple as file ownership and permissions. This is pretty much clear for anyone who knows some things about what the computer does. For people who only have some fuzzy ideas, fixing the Linux kernel to make (in this case) a virus work again sounded a bit weird.
Well, ransomware is in the news these days because of the raid in the Netherlands, and here there's another "security specialist" trying to use this for its PR. But again there is nothing that indicates that this is all about standard functionality. Yes, you can encrypt all your own files on a typical machine. Yes, a piece of software can do it for you. Yes, you can run such software. And if you're careless and follow orders easily, someone else might give you the software to do it.
"Once launched with administrator privileges, the Trojan loads into the memory of its process files containing cybercriminals' demands"
This sounds like it needs to run as root, is there any vulnerability involved and do I need to patch things?
Is it just a particularly crazy spam campaign that would somehow trick "website administrators" into running malware as root on their servers?
"Dr.Web Office Control access restriction system: Restricts or completely prohibits access to Internet resources and removable devices, and therefore, excludes the possibility of a virus invading via those sources."
"Users should only have access to the local resources they require to perform their jobs. It's no use trying to convince staff that flash drives are dangerous. It is much easier to centrally disable access to such devices."
If they are clever they would attack via wordpress and other systems that are unpatched and give shell access.
It seems its lacking any relevant information and is mostly some marketing for an antivirus vendor that tries to tell Linux users they need antiviruses, too.
No word on how it spreads. Also, unsurprisingly:
> Once launched with administrator privileges, etc.
If you do that, you kind of deserve to get infected...
> Doctor Web security researchers presume that at least tens of users have already fallen victim to this Trojan.
"presume" .. tens of users ..
Right, a bit more details on the infection vector would have helped to properly validate the concerns. But when you start presuming and pull numbers out of a high hat I'm almost ready to discard it.
The only thing we know now is that "something" needs to be run with admin privileges.
Just make sure your backups are OK.
Besides, once someone has root access to your *nix server, or at least privilege escalation (either of which would be required for this exploit to work), they already own you and can do whatever they want anyway. If you have a good backup scheme in place this is little more than a headache and a few hours of work to recover from. The only way I see this being a catastrophic exploit is if you end up with it on your home box with no offsite or air gapped backup. This holds true for Windows based ransomware attacks that do actually exist; nothing about this is unique, if it's even real.
Got to hand it to them, its actually a pretty cool attack vector.
edit: https://github.com/w8rbt/keycapDr Web are selling anti-virus. I'd like more info on how it infects systems.
Edit: You know, this is really ONLY being reported by Dr Web. Funny that.
https://www.virustotal.com/en/file/18884936d002839833a537921...
Enough evidence for me to believe that the malware exists. Apparently it uses mbed TLS for encryption and communicates via UDP.