Security researchers have discovered a new ransomware , dubbed NextCry . The ransomware targets customers of NextCloud software . NextCloud is designed for creating and using file hosting services 
The ransomware gets its name from the extensions it adds to encrypted files. Currently, the NextCry malware cannot be detected by antivirus .
xact64, a Nextcloud user affected by NextCry, has published some details about the ransomware in an attempt to find a solution to decrypt personal files.
xact64 explained that the sync process was updating his files to an encrypted version on the server.
“I immediately realized that my server was hacked and that my files were encrypted,” said xact64. “I tried to limit the damage (only 50% of my files were encrypted).”.
Researcher Michael Gillespie used the information shared by xact64 to analyze the malware .He confirmed that it is a new ransomwarethat uses Base64 to encode file names. The researcher also said that NextCry uses the AES-256 algorithm to encrypt files.
NextCry is a Python script, compiled into a Linux ELF binary, via pyInstaller.
The hackers behind the NextCry ransomware are demanding 0.025 BTC (about $210) from victims to decrypt their files. Researchers examined the bitcoin wallet provided by the hackersand found that none of the victims have paid the ransom yet.
Here is the message the hackers sent after installing NextCry and encrypting the files:

The researchers' analyses confirmed that the malicious code was designed exclusively to carry out attacks on NextCloud users
Upon execution, NextCry ransomware 's config.php file service NextCloud to find the NextCloud file share and sync data directory. Once it finds it, it deletes folders that can be used to restore files and encrypts all files in the data.
Four days ago, another user with the username "alexpw" also reported being affected by the ransomware. This user was running the latest version of the NextCloud software.
"A warning. There seems to be a problem with NextCloud and I can't access it. My server was already locked down using SSH keys and NextCloud was up to date," he wrote.
From the comment of this user, it appears that the hackers exploited some vulnerabilities in the server.
On October 24, Nextcloud published an urgent advisory for the CVE-2019-11043 RCE vulnerability in NGINX.
The warning read: “In the last 24 hours, a new risk in NGINX, a vulnerability called CVE-2019-11043. This exploit allows remote code execution in certain NGINX and php-fpm configurations. If you are not running NGINX, this exploit does not affect you.”
“Unfortunately, the default Nextcloud NGINX configuration is also vulnerable to this attack . ”
Nextcloud administrators are asked to update their PHP packages and NGINX configuration file.
