A new version of the Ryuk Ransomware was released that will purposely avoid encrypting folders commonly seen in *NIX operating systems. Blacklist *NIX Folders The list of Ryuk blacklisted *NIX folders are: bin boot Boot dev etc lib initrd sbin sys vmlinuz run var At first glance, it seems strange that a Windows malware would blacklist *NIX folders when encrypting files. Even stranger, Kremez told us that he has been asked numerous times whether there was a Unix variant of Ryuk as data stored in these operating systems have been encrypted in Ryuk attacks. With the rising popularity of WSL, the Ryuk actors likely encrypted a Windows machine at some point that also affected the *NIX system folders used by WSL. It is new to me and might explain why Ryuk and how Ryuk affects NIX machines via WSL," Kremez told BleepingComputer. As the goal of most successful ransomware is to encrypt a victim's data, but not affect the functionality of the operating system, this change makes sense With these folders being blacklisted, Ryuk eliminates an additional headache that they would need to deal with for a paying customer whose WSL installations are ruined.
from Cyware News - Latest Cyber News https://ift.tt/34YENfx
from Cyware News - Latest Cyber News https://ift.tt/34YENfx
Comments
Post a Comment