In an unexpected announcement, Clement Lefebvre, head of the Linux Mint project, stated that the Linux Mint website had been compromised and that hackers managed to tamper with, and distribute, a malicious ISO of Linux Mint 17.3 Cinnamon.
If you downloaded the Cinnamon version before Saturday and downloaded it from an HTTP link, you are at risk.
It's worth noting that since the breach was discovered, the malicious ISOs have been removed so it's safe to download the files again.
The blog by Lefebvre explains how users can check the MD5 signature for any ISO they think may be “tampered.”
Users who discover they have downloaded an infected ISO are now advised to delete it immediately, format the USB sticks that carried the file, or throw away the DVDs that burned it.
For those who used the ISO to install the operating system on their computer, things are much more dangerous..
If you are one of them, you should immediately proceed with the following steps:
Take your computer offline.
Back up your personal data.
Reinstall the operating system (from a clean ISO) or format the partition.
Change all passwords you used on your computer, on the Web, and especially on email accounts.
