As we reported in our recent article, researchers at Palo Alto Networks have discovered a malware called Xbash, which is a deadly cocktail of Cryptocurrency mining software, botnet, and ransomware combined into a single worm.
Xbash targets servers running on Linux or Windows and systems protected by weak passwords or devices operating with known vulnerabilities.
This new malware behaves differently based on the operating system it affects. Xbash presents itself as ransomware on Linux devices and creates botnets on them, while on Windows devices it takes the form of Cryptocurrency mining software.
Ransomware generally encrypts the victim's documents and demands payment in exchange for their restoration. But the problem is that the files are not always restored.
Like the infamous NotPetya, Xbash lacks any data recovery features. It demands a ransom after encryption, but even after the money is paid, the files remain encrypted.
So far, 48 people have fallen victim and paid nearly $6,000 in Bitcoin to the attackers. Therefore, Xbash is not exactly ransomware, as its real goal seems to be the complete destruction of the victim's data.
What makes Xbash truly dangerous is its ability to compromise an organization's intranet. This feature is not active, but once enabled, it exposes those networks and allows attackers to interfere with an organization's critical services.
According to security researchers, a group called Iron Group is behind the creation of the malware and is also linked to other ransomware attacks. The malware was first detected in May 2018 and four versions of Xbash have been found to date.
Since there is a difference in the code and time period across all versions, researchers believe that this malware is still under development. This means that attackers are adding more dangerous features or enabling the intranet targeting feature.
In any case, you should regularly back up important files and take the usual security measures to avoid falling victim to such attacks.
