Lilocked Ransomware
Lilocked, or Lilu, is a newly observed ransomware targeting Linux-based web servers. As of the time of publication, it has affected almost 7000 servers globally.
At present it is unclear how Lilocked identifies target systems, although it appears to be affecting systems running a variety of services including mail, CMS, and hosting servers.
Summary
Lilocked, or Lilu, is a newly observed ransomware targeting Linux-based web servers. As of the time of publication, it has affected almost 7000 servers globally.
At present it is unclear how Lilocked identifies target systems, although it appears to be affecting systems running a variety of services including mail, CMS, and hosting servers.
Affected platforms
The following platforms are known to be affected:
Threat details
At present it is unclear how Lilocked identifies target systems, although it appears to be affecting systems running a variety of services including mail, CMS, and hosting servers. Once installed, Lilocked will encrypt all reachable non-system files using an unknown algorithm before contacting a command and control server to confirm the encryption has been successful.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:54 pm