Team Nautilus has uncovered a Python-based ransomware attack that, for the first time, targets Jupyter Notebook, a popular tool used by data professionals.

See also: SunCrypt ransomware: New version with more features
Jupyter Notebook is an open source web environment for data visualization. The modular software is used for data modeling in data science, computing, and machine learning. The project supports more than 40 programming languages and is used by companies such as Microsoft, IBM, and Google, along with many universities.
Aqua Security's Nautilus team recently discovered malware that has targeted this popular data tool.
While Jupyter Notebook allows users to share their content with trusted contacts, access to the application is secured through account credentials or tokens. However, in the same way that enterprises sometimes fail to secure their AWS buckets, leaving them open for anyone to see, misconfigurations of Notebooks have also been detected.

Python ransomware targets those who have accidentally left their environment vulnerable.
The researchers created a honeypot containing an exposed Jupyter notebook application to observe the malware's behavior. The ransomware operator accessed the server, opened a terminal, downloaded a set of malicious tools — including the encryptors — and then manually created a Python script that executed the ransomware.
See also: Hive ransomware: Changes Linux VMware ESXi encryptor to Rust
While the attack stopped without finishing its job, Team Nautilus was able to grab enough data to simulate the rest of the attack in a lab environment. The encryptor would copy and then encrypt the files, delete any unencrypted content, and delete itself.
It should be noted that no ransom note was included as part of the package, which the team suspects indicates one of two things: either the attacker was experimenting with his honeypot creation, or the honeypot timed out before the ransomware attack was completed.
Overall, this attack is simple, unlike more sophisticated ransomware that uses advanced techniques, such as Locky, Ryuk, WannaCry, or ransomware-as-a-service like GandCrab.

Evidence suggests that the threat actor could be from Russia, and if it is the same attacker, it has been previously linked to cryptomining attacks on JupyterLab and Jupyter notebook environments.
See also: BEC scams cost victims more than ransomware
A search on Shodan reveals that several hundred internet-facing Jupyter Notebook environments are open and accessible. Of course, some of these may be honeypots, but not all. We believe that this attack may indicate a campaign running ransomware on these servers.
Information source: zdnet.com
