Popular Posts
-
Rackspace Hosting, Inc. (RAX) Raised to "Hold" at Zacks Investment Research ...
-
Bluehost WordPress Hosting Reviews: Best Low Cost Wordpress Friendly Web Hosting from ThreeHosts.comContact Center Solutions Industry News Sep 12, 2013 (PRWeb.com via COMTEX) -- Threehosts.com compares top blog hosting servi...
-
Large or small, every business needs a website. A company without a Web presence leaves many opportunities on the table, as a well-designe...
-
MilesWeb is a web hosting company based in India offering fully managed web hosting services in India, UK, US and Romania. The product and...
-
European leading web hosting provider, HostForLIFE.eu announces support for DotNetNuke 7.4.1 hosting plan due to high demand of DotNetNu...
-
Web hosting companies in UK rent space on their servers for your website data to be stored on and allow users to access it through the W...
-
JACKSONVILLE, Fla., June 09, 2016 (GLOBE NEWSWIRE) -- Web.com (NASDAQ:WEB), a leading provider of Internet services and online marketing...
-
Starting a web hosting business is a great way to operate a company that will provide a valuable service to both individuals and fellow ...
-
I want to share something from the first chapter of my upcoming book Front-end Development with ASP.NET Core, Angular, and Bootstrap. Wh...
-
Tweet Rackspace Hosting (NYSE:RAX) shares traded up 4.8% during mid-day trading on Wednesday following insider buying activity, M...
Blog Archive
- December (19)
- November (25)
- October (28)
- September (26)
- August (28)
- July (31)
- June (26)
- May (27)
- April (28)
- March (30)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (29)
- August (44)
- July (56)
- June (53)
- May (54)
- April (48)
- March (55)
- February (44)
- January (3)
- December (5)
- November (5)
- October (26)
- September (25)
- August (29)
- July (26)
- June (18)
- September (1)
About Me
Total Pageviews
Web-hosting firm agrees to pay over $1 million to ransomware extortionists
Nayana, a South Korean web hosting firm, was hit hard by a ransomware attack earlier this month which hit over 153 of its Linux servers, and impacting over 3,400 websites the company hosts for its business customers.
Nayana's systems are thought to have been hit by a Linux variant of the Erebus ransomware, designed to encrypt files on web servers and demand a payment for the data's safe return. In all, Erebus hints for 433 different file types on web servers – including documents, databases, images and videos.
Two weeks later, Nayana is still attempting to recover normal operations for its customers and has been posting updates on its forum detailing its progress.
Initially, the criminals behind the ransomware attack demanded 550 Bitcoins (approximately US $1.6 million):
My boss tell me, you buy many machine, give you a good price 550 BTCIf you do not have enough money, you need make a loan
You company have 40+ employees, every employee's annual salary $ 30,000all employees 30,000 * 40 = $ 1,200,000all server 550BTC = $ 1,620,000
If you can not pay that, you should go bankrupt.But you need to face your child, wife, customers and employees.Also, you will lose your reputation, business.You will get many more lawsuits.
After some negotiation, however, the ransom demand was reduced to 397.6 Bitcoins (a little more than US $1 million).

Of course, even that is a considerable amount of money for a victim of a cybercrime to pay out. Because of a lack of available funds, Nayana has agreed with the blackmailers to pay the ransom in three installments and – according to ZDNet – lent shares in Nayana to a firm which has previously been interested in acquiring the web-hosting business.
Obviously, questions must be asked as to why Nayana had to resort to paying criminals for the safe return of its data, and why it felt it wasn't in a position to restore customers' servers from secure backups in a timely fashion instead.
But more than that there remains the question of just how Nayana's servers managed to be compromised so thoroughly. Researchers at Trend Micro report that Nayana's Apache web servers appear to have been left unpatched for years, leaving them vulnerable to exploitation via well-known security holes that could have given an attack root access.
Whether that is the route through which Erebus managed to sneak its way onto Nayana's systems with such dramatic effect is uncertain, but what is clear is that if any company leaves itself unpatched and unprotected it is constantly in danger of being attacked again and again and again.
Ransomware isn't going away. It's one of the most effective ways for online criminals to make themselves a fortune. Ensure that you are properly protecting the computers you are responsible for, making regular secure backups, and deploying layered security measures to reduce the risk.
Author Graham Cluley, We Live Security
Source: Web-hosting firm agrees to pay over $1 million to ransomware extortionists
0 comments:
Post a Comment