HomeSecurityClop ransomware for Linux: Flaw allows file recovery

Clop ransomware for Linux: Flaw allows file recovery

The Clop ransomware operation now also uses a variant of the malware that only targets Linux servers, but a flaw in the encryption system allows victims to recover their files without paying a ransom.

See also: Exclu: Dutch police hacked the communication platform

Clop ransomware linux

See also: GoAnywhere MFT zero-day: Fortra released patch

In December 2022, SentinelLabs researcher Antonis Terefos discovered the new Linux version of Clop while investigating an attack on a university in Colombia. This happened at the same time as its use alongside the Windows variant by the same threat group.

While the Windows and Linux versions of the encryption method are nearly identical, with nearly identical process logic, some minor differences remain. These differences mainly stem from OS API calls and features that have not yet been integrated into the Linux version.

Clop's Linux malware is in its early stages due to the lack of protective obfuscation and evasion techniques, as well as multiple vulnerabilities that allow victims to recover their data without the need for monetary compensation.

Targeting Oracle database servers

Launching the Clop ransomware Linux executable (ELF) creates a new process that attempts to gain advanced privileges and encrypt your data.

The files and folders targeted include the user's "/home" directory, which contains all personal files, the "/root" and "/opt" directories, and the Oracle directories ("/u01" - "/u04") used to store database files or as mount points for Oracle software.

The specific targeting of Oracle database folders is not commonly seen in Linux ransomware encryptors, which typically focus on encrypting ESXi virtual machines.

The Linux variant also does not support the hashing algorithm used by the Windows version to exclude certain types of files and folders from encryption. There is also no mechanism for treating files of different sizes differently in Linux.

The Linux version of Clop lacks several features that could prove very useful, such as drive enumeration that could help identify the starting point for recursive folder encryption and command line parameters that offer increased control over encryption.

See also: Tinder: Strengthens online safety with real-time updates

Clop ransomware for Linux: Flaw allows file recovery

Encryption flaws

The current Linux version will not encrypt and RC4 keys used to encrypt files with the RSA-based asymmetric algorithm used in the Windows variant.

In contrast, in the Linux version, Clop uses a hardcoded RC4 "master key" to generate the encryption keys and then uses the same key to encrypt and store it locally in the file. Also, the RC4 key is never validated, whereas on Windows it is validated before encryption begins.

This weak arrangement does not protect the keys from free recovery and the encryption from reversal, which SentinelLabs did (a Python script that does exactly this is now available on GitHub).

Clop ransomware linux

In addition to the lack of key security, SentinelLabs discovered that when the encrypted key is written to a file, the malware also writes some additional data, such as details about the file, such as the size and encryption time.

This data should be hidden, as it could help experts perform targeted decryption of specific, valuable files.

Clop ransomware linux

Although the Clop ransomware for Linux is unlikely to pose a widespread threat in its current form, the availability of a decryptor will undoubtedly motivate its creators to release secure and superior versions with a suitably secure encryption framework.

Despite its weaknesses, the use of the Linux variant in real Clop attacks demonstrates that, for threat actors, having a Linux version, even an easily compromised one, is still preferable to not being able to attack Linux systems within target organizations.

Linux malware is a growing threat that should not be ignored by computer users who rely on this popular open-source operating system. By following best practices, such as regularly installing security patches, using strong passwords and antivirus software with real-time scanning capabilities, frequently backing up your data, and avoiding suspicious links or downloads in emails or websites you regularly visit, you can ensure that your system remains safe from attacks by cybercriminals who seek to exploit vulnerabilities in the Linux operating system.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS