HomeinetXbash: New malware family targets Linux and Windows

Xbash: New malware family targets Linux and Windows

Xbash: Palo Alto Networks' Unit 42 research team has discovered a new class of malware that targets Linux and Windows systems.

The reason is the Xbash family of malware associated with the Iron Group, known for several ransomware attacks.

Xbash has been observed to spread between servers using a combination of exploitable vulnerabilities and brute force attacks and, unlike other ransomware, comes with data destruction features enabled by default with no recovery feature, making file recovery practically impossible.

Additionally, Xbash's botnet and ransomware components target Linux servers, exploiting unprotected and vulnerable services that have not yet been registered, immediately deleting MySQL, PostgreSQL, and MongoDB databases, and demanding Bitcoin to (hypothetically) restore the data.

Xbash

Furthermore, Xbash has the ability to spread just like Petya/NoPetya and WannaCry.

Xbash also comes with detection capabilities based on syntax, compression, conversion, as well as code encryption, with the common goal of subverting malicious behavior so that it cannot be detected by antiviruses.

Unit 42 has already found 48 incoming transactions in Xbash encrypted wallets, totaling $6000, meaning the new malware family is already active and collecting ransoms from victims.

What you have to do to protect yourself is to use strong passwords, always install security updates for the operating system, create backups as often as possible, and limit access to unknown remote servers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS