An attack has been launched on the Linux server and a new variant of IceFire, the blackmail software for Win10 / Win11, has emerged.
CTOnews.com March 11 news, IceFire is a well-known blackmail software for the Windows platform. According to the latest report released by SentinelLabs, there is a new variant of the ransomware that can also launch extortion attacks on the Linux platform.
Attackers exploited deserialization vulnerabilities in IBM Aspera Faspex file sharing software to attack servers in multiple media and entertainment departments around the world by spreading IceFire variants.
Once Linux devices and servers are infected with IceFire variants, they will encrypt the data and add the ".ifire" extension to the file. CTOnews.com learned from the report that the IceFire variant does not infect all files on the device, but bypasses key parts of the system to keep the system running, but encrypts user data.
Once the blackmail software has finished encrypting the data, it will issue a blackmail notice asking the victim to contact the attacker within five days. If the victim chooses not to pay the ransom, the victim's data will be made public online.