JungleSec Ransomware
JungleSec is a ransomware tool that has been spread via unsecured Intelligent Platform Management Interface (IPMI) systems since November 2018.
Summary
JungleSec is a ransomware tool that has been spread via unsecured Intelligent Platform Management Interface (IPMI) systems since November 2018.
Affected platforms
The following platforms are known to be affected:
Threat details
Remote attackers can take control of servers and other devices using IPMI where they have not been properly configured, particularly when default credentials have not been changed. JungleSec has been found on Windows, Linux and Mac devices.
When the threat actors gain access to a device, they reboot it into single user mode to acquire root privileges. They then download, compile and execute the ccrypt program to encrypt files hosted on the device. Virtual machine disks may also be encrypted.
A ransom note is saved to the affected device that demands payment in bitcoin. A message is attached to the sudo command that prompts users to read this file. Users who pay the ransom report that they are still unable to recover their data. A backdoor is installed in some attacks that listens for activity on TCP port 64321, with a firewall rule being created to allow access to that port.
Remediation steps
| Type | Step |
|---|---|
|
IPMI systems should be properly secured so that they cannot be utilised to compromise a device:
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:54 pm