www.rivitmedia.comwww.rivitmedia.comwww.rivitmedia.com
  • Home
  • Tech News
    Tech NewsShow More
    Microsoft’s May 2025 Patch Tuesday: Five Actively Exploited Zero-Day Vulnerabilities Addressed
    7 Min Read
    Malicious Go Modules Unleash Disk-Wiping Chaos in Linux Supply Chain Attack
    4 Min Read
    Agentic AI: Transforming Cybersecurity in 2025
    3 Min Read
    Cybersecurity CEO Accused of Planting Malware in Hospital Systems: A Breach of Trust That Shocks the Industry
    6 Min Read
    Cloud Convenience, Criminal Opportunity: How Google Sites Became a Launchpad for Elite Phishing
    6 Min Read
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
    • Microsoft CVE Errors
  • How-To-Guides
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
  • FREE SCAN
  • Cybersecurity for Business
Search
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2023 rivitMedia.com. All Rights Reserved.
Reading: RansomExx Ransomware Expands its Reach to Linux Machines and Attacks Brazilian Courts
Share
Notification Show More
Font ResizerAa
www.rivitmedia.comwww.rivitmedia.com
Font ResizerAa
  • Online Scams
  • Tech News
  • Cyber Threats
  • Mac Malware
  • Cybersecurity for Business
  • FREE SCAN
Search
  • Home
  • Tech News
  • Cyber Threats
    • Malware
    • Ransomware
    • Trojans
    • Adware
    • Browser Hijackers
    • Mac Malware
    • Android Threats
    • iPhone Threats
    • Potentially Unwanted Programs (PUPs)
    • Online Scams
  • How-To-Guides
  • Product Reviews
    • Hardware
    • Software
  • IT/Cybersecurity Best Practices
    • Cybersecurity for Business
  • FREE SCAN
  • Sitemap
Follow US
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
www.rivitmedia.com > Blog > Cyber Threats > Ransomware > RansomExx Ransomware Expands its Reach to Linux Machines and Attacks Brazilian Courts
RansomwareTech News

RansomExx Ransomware Expands its Reach to Linux Machines and Attacks Brazilian Courts

riviTMedia Research
Last updated: October 20, 2023 6:23 am
riviTMedia Research
Share
New SEC Rules Go Into Effect in December.
SHARE

In November of 2020, RansomExx was involved in the attacks against Brazil’s Superior Court of Justice. Also, the RansomExx ransomware operators have expanded their reach by developing a Linux version of the malware. RansomEXX is human-operated ransomware that, in June 2020, was used in an attack on the Texas Department of Transportation. In August of 2020, it infected systems at the multinational technology Konica Minolta. While in September of 2020, it was involved in an attack against IPG Photonics high-performance laser developer and software provider Tyler Technologies. The new Linux version of RansomExx ransomware is built as an ELF executable named ‘svc-new’ that encrypts the target’s server. 

According to Kaspersky Labs: “After the initial analysis, we noticed similarities in the code of the Trojan, the text of the ransom notes and the general approach to extortion, which suggested that we had in fact encountered a Linux build of the previously known ransomware family RansomEXX.” 

Upon launching the Trojan, a 256-bit key is generated that encrypts all the victim’s files that it can reach using the AES block cipher in ECB mode. The AES key is encrypted by a public RSA-4096 key embedded in the malware’s code and appended to all encrypted files. The ransomware lacks other functionalities executed by other Trojans, such as anti-analysis features, C2 communication, and the ability to kill processes. Unlike the Windows version, the Linux strain doesn’t wipe free hard drive space. When victims pay the ransom, they receive both a Linux and Windows decryptor with the corresponding RSA-4096 private key and encrypted file extension. 

In the fall of 2020, Brazil’s Superior Court of Justice was temporarily shut down by RansomExx. The ransomware attack forced a temporary shutdown of the court’s information technology network. 

“The Superior Court of Justice (STJ) announces that the court’s information technology network suffered a hacker attack, this Tuesday (3), during the afternoon, when the six group classes’ judgment sessions were taking place. The presidency of the court has already called the Federal Police to investigate the cyber attack.” announced STJ President Humberto Martins in an official statement on the Supreme Federal Court’s website.

The attack was discovered on November 3rd, and IT staff shut down the court’s network to prevent the spread of the malware. All court sessions, virtual and by video conference, were either suspended or canceled until the court network’s security was restored. As a result of this devastating attack, the websites for several Brazilian federal government agencies were also forced to go offline.

You Might Also Like

Ways Cybercriminals are Trying to Steal Your Vote
Remove RedLocker Virus [.redlocker Files]
Tisc Ransomware Encrypts Victims’ Files Before Demanding a Ransom
Rigd Ransomware is One More Variant from the Prolific STOP/Djvu Ransomware
Huntransomware Cyber Threat: Detection, Consequences, and Removal Guide
TAGGED:ransomwareTech News

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Copy Link Print
Share
Previous Article How Employee Error & Negligence Can Compromise Your Business’s Cyber Security 
Next Article malware macOS Bundlore Loader Avoids Detection by Hiding its Payload Within a Named Fork
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Scan Your System for Free

✅ Free Scan Available 

✅ 13M Scans/Month

✅ Instant Detection

Download SpyHunter 5
Download SpyHunter for Mac

//

Check in Daily for the best technology and Cybersecurity based content on the internet.

Quick Link

  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

www.rivitmedia.comwww.rivitmedia.com
© 2023 • rivitmedia.com All Rights Reserved.
  • ABOUT US
  • TERMS AND SERVICES
  • SITEMAP
  • CONTACT US