Home > Cyber News > RansomEXX Ransomware Is Now Targeting Linux Systems

RansomEXX Ransomware Is Now Targeting Linux Systems

Kaspersky researchers recently discovered new ransomware targeting Linux systems. The team came across a 64-bit ELF executable designed to encrypt data on Linux-running machines.

The analysis shows that the ransomware shares many similarities with a previously known family called RansomEXX. These similarities mean that the ransomware now has a Linux build. RansomEXX is known for its targeted attacks against large corporations, most of which took place last year. In fact, Kaspersky says that “RansomEXX is a highly targeted Trojan.” Companies victimized by RansomEXX include the Texas Department of Transportation and Konica Minolta.

RansomEXX Linux Version

Once the ransomware is launched on the targeted Linux machine, it generates a 256-bit key to encrypt all data it can reach via the AES block cipher in ECB mode. The AES key is then encrypted by a public RSA-4096 key, which is embedded in its body and appended to all encrypted files.

In terms of encryption, the ransomware also regenerates and re-encrypts the AES key every 0.8 seconds. Kaspersky’s analysis, however, shows that the keys only differ every second. Despite strong encryption efforts, the Linux build of RansomEXX lacks command-and-control infrastructure, termination of running processes, and anti-analysis. These features are typical for most ransomware Trojans.

Despite the fact that previously discovered PE builds of RansomEXX use WinAPI (functions specific to Windows OS), the organization of the Trojan’s code and the method of using specific functions from the mbedtls library hint that both ELF and PE may be derived from the same source code, the researchers say.

Previous Windows version of RansomEXX used the .txd0t extension

The team also noticed “resemblances in the procedure that encrypts the file content, and in the overall layout of the code.” The ransom note is also nearly identical to the Windows variant.

One of the latest versions of the Windows-targeting RansomEXX appended the .txd0t extension to encrypted files. The ransomware was used in a dangerous attack against a large US company called Tyler Technologies, a public sector software provider and services provider. The cybercriminals rendered the company’s website inactive.

The security staff detected an intrusion into the company’s network on September 23, 2020. Fortunately, no customer data was accessed by the hackers. All compromised information appears to be limited to the internal network and phone systems of the company.

Milena Dimitrova

An inspired writer and content manager who has been with SensorsTechForum since the project started. A professional with 10+ years of experience in creating engaging content. Focused on user privacy and malware development, she strongly believes in a world where cybersecurity plays a central role. If common sense makes no sense, she will be there to take notes. Those notes may later turn into articles! Follow Milena @Milenyim

More Posts

Follow Me:

Leave a Comment

Your email address will not be published. Required fields are marked *

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share