Popular Posts
-
I would like to bring another one of my skills to the table, WordPress baby! Starting with this post I will be covering the basics, doma...
-
Whenever a website is made you have to pay for the host and domain. There are different payment plans, sometimes every month and sometim...
-
re: purchasing WordPress.COM upgrades WordPress.com provides free blogs and hosts them free of charge. There are no bandwidth charges. A...
-
ASPHostPortal.com - The leader of ASP.NET hosting provider launches ASP.NET 4.6 hosting with fast network and fast support. New York, ...
-
CrowdReviews.com Announces Guide for Selecting Web Hosting Companies SOURCE: CrowdReviews.com July 23...
-
Grandi expresses his gratitude to Kenya for hosting almost half a million refugees and keeping its borders open to people fleeing war. B...
-
danroo 6 hours ago Template 59 Views HostWHMCS is a Responsive Web Hosting and WHMCS Template designed for All kinds of Domain an...
-
HOSTIO is a readymade web hosting WordPress theme for immediate use — created as straight forward as it can be. It's built with mode...
-
Introduction With .NET Core 1.0 fresh off the press, the Windows developer in me that has a decade-long experience with C# is thrilled by...
-
April 28, 2016 04:00 ET | Source: Research and Markets Dublin, April 28, 2016 (GLOBE NEWSWIRE) -- Research and Markets has announ...
Blog Archive
- December (19)
- November (25)
- October (28)
- September (26)
- August (28)
- July (31)
- June (26)
- May (27)
- April (28)
- March (30)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (29)
- August (44)
- July (56)
- June (53)
- May (54)
- April (48)
- March (55)
- February (44)
- January (3)
- December (5)
- November (5)
- October (26)
- September (25)
- August (29)
- July (26)
- June (18)
- September (1)
About Me
Total Pageviews
Web-hosting firm agrees to pay over $1 million to ransomware extortionists
Nayana, a South Korean web hosting firm, was hit hard by a ransomware attack earlier this month which hit over 153 of its Linux servers, and impacting over 3,400 websites the company hosts for its business customers.
Nayana's systems are thought to have been hit by a Linux variant of the Erebus ransomware, designed to encrypt files on web servers and demand a payment for the data's safe return. In all, Erebus hints for 433 different file types on web servers – including documents, databases, images and videos.
Two weeks later, Nayana is still attempting to recover normal operations for its customers and has been posting updates on its forum detailing its progress.
Initially, the criminals behind the ransomware attack demanded 550 Bitcoins (approximately US $1.6 million):
My boss tell me, you buy many machine, give you a good price 550 BTCIf you do not have enough money, you need make a loan
You company have 40+ employees, every employee's annual salary $ 30,000all employees 30,000 * 40 = $ 1,200,000all server 550BTC = $ 1,620,000
If you can not pay that, you should go bankrupt.But you need to face your child, wife, customers and employees.Also, you will lose your reputation, business.You will get many more lawsuits.
After some negotiation, however, the ransom demand was reduced to 397.6 Bitcoins (a little more than US $1 million).
Of course, even that is a considerable amount of money for a victim of a cybercrime to pay out. Because of a lack of available funds, Nayana has agreed with the blackmailers to pay the ransom in three installments and – according to ZDNet – lent shares in Nayana to a firm which has previously been interested in acquiring the web-hosting business.
Obviously, questions must be asked as to why Nayana had to resort to paying criminals for the safe return of its data, and why it felt it wasn't in a position to restore customers' servers from secure backups in a timely fashion instead.
But more than that there remains the question of just how Nayana's servers managed to be compromised so thoroughly. Researchers at Trend Micro report that Nayana's Apache web servers appear to have been left unpatched for years, leaving them vulnerable to exploitation via well-known security holes that could have given an attack root access.
Whether that is the route through which Erebus managed to sneak its way onto Nayana's systems with such dramatic effect is uncertain, but what is clear is that if any company leaves itself unpatched and unprotected it is constantly in danger of being attacked again and again and again.
Ransomware isn't going away. It's one of the most effective ways for online criminals to make themselves a fortune. Ensure that you are properly protecting the computers you are responsible for, making regular secure backups, and deploying layered security measures to reduce the risk.
Author Graham Cluley, We Live Security
Source: Web-hosting firm agrees to pay over $1 million to ransomware extortionists
0 comments:
Post a Comment