Popular Posts
-
If you're a beginner just starting a WordPress blog, then there's no need to get VPS hosting. A shared hosting plan will provide a...
-
BI Intelligence See Also The Internet of Everything — $12.6 trillion ROI expected over the next decade [SLIDE DECK] T...
-
US 01:36 15.04.2016Get short URL Marco Marsala seemingly lost all traces of his company, including the websites that he works with, b...
-
29.06.2015 11:09:04 - SpamExperts adds Dutch web host Networking4all to Hosting Partner Program (live-PR.com) - Amsterdam, June 29, 2015 – D...
-
2017-08-22 Sports News of Tue, 22 Aug 20170 Tamale ready to host 2017 MTN FA Cup final - RFA Chairman File photo Mr. Abdoula...
-
There are many web hosting companies out there, all claiming to be the best. How do you choose the one that will meet your needs? The Smal...
-
WebHostingCat.com has published their web hosting recommendations for 2017. The annual list was released to assist consumers that are plan...
-
We are presenting the best free web hosting that the world has ever known. Free Unlimited Web Hosting, No Ads, Real cPanel, MySQL, PHP. Crea...
-
wedmfm.com is a wordpress.ORG software install on paid hosting, hosted by Bluehost, not by wordpress.COM. Contact your web host. You are...
-
Rackspace Hosting (NYSE: RAX) has recently received a number of price target changes and ratings updates: 7/14/2015 – Rackspace Hosting ...
Blog Archive
- December (19)
- November (25)
- October (28)
- September (26)
- August (28)
- July (31)
- June (26)
- May (27)
- April (28)
- March (30)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (29)
- August (44)
- July (56)
- June (53)
- May (54)
- April (48)
- March (55)
- February (44)
- January (3)
- December (5)
- November (5)
- October (26)
- September (25)
- August (29)
- July (26)
- June (18)
- September (1)
About Me
Total Pageviews
Web-hosting firm agrees to pay over $1 million to ransomware extortionists
Nayana, a South Korean web hosting firm, was hit hard by a ransomware attack earlier this month which hit over 153 of its Linux servers, and impacting over 3,400 websites the company hosts for its business customers.
Nayana's systems are thought to have been hit by a Linux variant of the Erebus ransomware, designed to encrypt files on web servers and demand a payment for the data's safe return. In all, Erebus hints for 433 different file types on web servers – including documents, databases, images and videos.
Two weeks later, Nayana is still attempting to recover normal operations for its customers and has been posting updates on its forum detailing its progress.
Initially, the criminals behind the ransomware attack demanded 550 Bitcoins (approximately US $1.6 million):
My boss tell me, you buy many machine, give you a good price 550 BTCIf you do not have enough money, you need make a loan
You company have 40+ employees, every employee's annual salary $ 30,000all employees 30,000 * 40 = $ 1,200,000all server 550BTC = $ 1,620,000
If you can not pay that, you should go bankrupt.But you need to face your child, wife, customers and employees.Also, you will lose your reputation, business.You will get many more lawsuits.
After some negotiation, however, the ransom demand was reduced to 397.6 Bitcoins (a little more than US $1 million).
Of course, even that is a considerable amount of money for a victim of a cybercrime to pay out. Because of a lack of available funds, Nayana has agreed with the blackmailers to pay the ransom in three installments and – according to ZDNet – lent shares in Nayana to a firm which has previously been interested in acquiring the web-hosting business.
Obviously, questions must be asked as to why Nayana had to resort to paying criminals for the safe return of its data, and why it felt it wasn't in a position to restore customers' servers from secure backups in a timely fashion instead.
But more than that there remains the question of just how Nayana's servers managed to be compromised so thoroughly. Researchers at Trend Micro report that Nayana's Apache web servers appear to have been left unpatched for years, leaving them vulnerable to exploitation via well-known security holes that could have given an attack root access.
Whether that is the route through which Erebus managed to sneak its way onto Nayana's systems with such dramatic effect is uncertain, but what is clear is that if any company leaves itself unpatched and unprotected it is constantly in danger of being attacked again and again and again.
Ransomware isn't going away. It's one of the most effective ways for online criminals to make themselves a fortune. Ensure that you are properly protecting the computers you are responsible for, making regular secure backups, and deploying layered security measures to reduce the risk.
Author Graham Cluley, We Live Security
Source: Web-hosting firm agrees to pay over $1 million to ransomware extortionists
0 comments:
Post a Comment