As for how this Linux ransomware arrives, we can only infer that Erebus may have possibly leveraged vulnerabilities or a local Linux exploit. For instance, based on open-source intelligence, 2048 bitcoin scam sites’s website runs on Linux kernel 2. 2, which was compiled back in 2008.

Additionally, NAYANA’s website uses Apache version 1. 4, both of which were released back in 2006. It’s worth noting that this ransomware is limited in terms of coverage, and is, in fact, heavily concentrated in South Korea. These submissions can also indicate they were from other security researchers. The file is first scrambled with RC4 encryption in 500kB blocks with randomly generated keys. The RC4 key is then encoded with AES encryption algorithm, which is stored in the file.

The AES key is again encrypted using RSA-2048 algorithm that is also stored in the file. While each encrypted file has its RC4 and AES keys, the RSA-2048 public key is shared. These RSA-2048 keys are generated locally, but the private key is encrypted using AES encryption and another randomly generated key. Ongoing analysis indicates that decryption is not possible without getting hold of the RSA keys.

Office documents, databases, archives, and multimedia files are the usual file types targeted by ransomware. It’s the same for this version of Erebus, which encrypts 433 file types. Here is a table that shows the directories and system tablespaces that Erebus searches. Given the risks to business operations, reputation, and bottom line, enterprises need to be proactive in keeping threats like ransomware at bay.

We will update this post as more information from our analysis of this Linux ransomware become available. Attackers are banking on network vulnerabilities and inherent weaknesses to facilitate massive malware attacks, IoT hacks, and operational disruptions. The ever-shifting threats and increasingly expanding attack surface will challenge users and enterprises to catch up with their security. Read our security predictions for 2018. Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

