HomeSecurityThousands of servers have been infected by the new Lilocked ransomware

Thousands of servers have been infected by the new Lilocked ransomware

Lilocked A new ransomware has been used by hackers to carry out attacks on thousands of web servers. The ransomware is called Lilocked or Lilu and has already encrypted thousands of files.

The hackers behind the Lilocked ransomware have reportedly been launching attacks since mid-July. However, in the past two weeks, the attacks have become more frequent.

Based on the evidence available so far, Lilocked ransomware only targets Linux systems.

As we mentioned above, the first attacks occurred in mid-July. The case was reported by ID Ransomware, a site that helps victims find out the name of the ransomware that has infected their computer. Some of the Lilocked victims posted the ransom message sent by the hackers on the site. This is how the new ransomware became known.

Researchers have not yet determined how the hackers breached the servers and encrypted the data, but some suggest they may be targeting systems with outdated Exim software.

The ransomware is also said to have gained access with administrator privileges.

Servers infected with Lilocked ransomware stand out from others, as most of their files are encrypted and display a new “.lilocked” file extension:

Thousands of servers have been infected by the new Lilocked ransomware

The hackers have placed a copy of the ransom message (# README.lilocked) in all folders containing encrypted files.

Thousands of servers have been infected by the new Lilocked ransomware

Users are taken to a portal on the dark web. In the ransom message, there is a “key” that users must use. At this point, the hackers ask for more money (0.03 bitcoin, or about $325).

Thousands of servers have been infected by the new Lilocked ransomware

Thousands of servers have been infected by the new Lilocked ransomware

According to the evidence available so far, Lilocked ransomware does not affect system files. It encrypts only a small subset of file extensions, such as HTML, SHTML, JS, CSS, PHP, INI and various image file formats.

Since system files are not affected, infected servers continue to function normally. Lilocked ransomware has infected more than 6,700 servers.

Unfortunately, there is no reliable information on how hackers manage to infect servers. Thus, specific instructions cannot be given to server owners on what to watch out for. General advice applies, such as using unique passwords for different accounts and regularly updating all systems and applications.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS