B0r0nt0K Ransomware
B0r0nt0K is a newly observed ransomware tool targeting unsecured Linux and Windows web servers.
Summary
B0r0nt0K is a newly observed ransomware tool targeting unsecured Linux and Windows web servers.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how B0r0nt0K is delivered to target devices, although there are unconfirmed reports indicating it may be distributed manually using known exploits.
Once delivered, B0r0nt0K will encrypt all non-system files, using an unknown cipher, before further encoding the files in Base64. Filenames are also encrypted in the same manner before being percent-encoded (commonly referred to as URL encoding) and appended with a new extension.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:50 pm