HomeinetWeb Hosting Company Pays $1 Million to Ransomware

Web Hosting Company Pays $1 Million to Ransomware

A web hosting company agreed to pay 1 million dollars in bitcoins to the hackers who managed to infect its 153 Linux servers with ransomware, encrypting 3,400 websites and all the data they hosted.

According to a blog post by South Korean web hosting company NAYANA, the unfortunate event occurred on June 10th, when ransomware hit the hosting servers. The attacker or attackers initially demanded 550 bitcoins (over $1.6 million) to unlock the encrypted files.Web Hosting

However, the company negotiated with the criminals and agreed to pay 397,6 bitcoins (approximately 1,01 million dollars) in three installments to decrypt their files.

The Web Hosting company has already paid the two installments at this time and will pay the final installment after retrieving data from two thirds of its infected servers.

According to the security company Trend Micro, the ransomware used in the attack was Erebus, which first appeared last September and was upgraded in February of the current year with capabilities to bypass User Account Control.

The hosting servers were running the Linux kernel 2.6.24.2, and researchers believe that the Erebus Linux ransomware was able to exploit known vulnerabilities such as DIRTY COW.

“The Web Hosting company NAYANA uses Apache version 1.3.36 and PHP version 5.1.4. Both were released in 2006.”

Erebus is a ransomware that primarily targets users in South Korea, encrypting Office documents, databases, and media files using the RSA-2048 algorithm. It then adds the .ecrypt extension to the infected files before displaying the ransom note.

According to the analysis conducted by Trend Micro researchers, decryption of infected files is not possible without the RSA keys.

Let's reiterate: the only surefire way to deal with ransomware attacks is prevention. The best defense against Ransomware is user education and maintaining backups.

Most malicious software hits if you open infected attachments or click on links to malicious programs that usually come in email messages.

Make sure your systems are running the latest available version.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS