Sunday 30 September 2018, Poradnik bezpieczeństwa

Xbash – a new all-in-one botnet – targets Windows and Linux with ransomware and cryptomining

Lost24

Researchers discovered a new malware, named Xbash, targeting servers of various platforms, with four different versions seen in the wild actively seeking unprotected services, exploiting vulnerabilities, and deleting databases in modern OS systems.

A newly discovered malware was reported to have combined ransomware, coinminer, botnet and worm feature together.

The malware attacks both Windows and Linux systems in different ways. It deletes database on Linux while mines for cryptocurrency on Windows.

Generally, Xbash malware is likely to attack the system that is protected with a weak password or running with unpatched known vulnerabilities. On Linux, researcher found that Xbash malware is clearly instructed to delete the victim’s database. However, Xbash malware doesn’t really store the encrypted data. On windows, Xbash malware targets mainly on mining for cryptocurrency or asking for a ransom.

Since the main targets of Xbash malware are systems with weak passwords or devices operating with unpatched vulnerabilities. The users may prevent their systems from being attacked by setting more secure passwords, install newest OS security patches, and by providing for effective malware removal software. As Xbash malware is an online threat and aims at mining for cryptocurrency, a malware blocker should be a must in preventing your system from being encrypted.