IceFire Ransomware Targets Linux Enterprise Networks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-47986 | YAML Deserialization RCE in IBM Aspera Faspex IBM Aspera Faspex, an enterprise high-speed file transfer platform, contains a deserialization flaw (CWE-502) that allows a remote attacker to execute code on the server by supplying crafted input that the application insecurely deserializes as YAML. An attacker who can reach the Faspex application can trigger the flaw and run arbitrary code in the context of the application, potentially leading to full compromise of the hosting server. Any organization running IBM Aspera Faspex is affected, with internet-exposed deployments at greatest risk since they provide direct reachability to the vulnerable application. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-02-21 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (top percentile). No public proof-of-concept is catalogued, but confirmed in-the-wild exploitation makes patching urgent. Do: Apply IBM's update for Aspera Faspex per vendor instructions as the required action, prioritizing any Faspex instance reachable from the internet; restrict network access (firewall/VPN) until patched. Because ransomware actors have used this flaw, also review Faspex servers for signs of compromise, such as unexpected processes spawned by the application, anomalous requests to Faspex application endpoints, or new accounts and persistence mechanisms. | 9.8 | 100% | KEV ransomware |
| moderate≈1,000–5,000 Faspex deployments, with on the order of a thousand or more internet-exposed (order-of-magnitude estimate) |
Full article362 words · extracted from infosecurity-magazine.com · click to collapse
New Linux versions of the IceFire ransomware were deployed in February, against enterprise networks of several media and entertainment sector organizations worldwide.
According to security researchers at SentinelOne, the campaign leveraged the exploitation of CVE-2022-47986, a recently patched deserialization vulnerability in IBM Aspera Faspex file-sharing software.
“The operators of the IceFire malware, who previously focused only on targeting Windows, have now expanded their focus to include Linux,” wrote SentinelOne senior threat researcher Alex Delamotte in Thursday’s advisory.
The move represents a strategic shift, says the security researcher, that aligns the IceFire group with other ransomware groups that have also evolved to target Linux systems.
“In comparison to Windows, Linux is more difficult to deploy ransomware against, particularly at scale,” Delamotte wrote. “Many Linux systems are servers: typical infection vectors like phishing or drive-by download are less effective. To overcome this, actors turn to exploiting application vulnerabilities.”
In the most recent attacks observed by SentinelOne, upon execution, the IceFire Linux version downloaded two separate payloads that encrypt files and then delete the malware.
“IceFire ransomware doesn’t encrypt all files on Linux: it avoids encrypting certain paths so that critical parts of the system are not encrypted and remain operational,” explained Delamotte.
“Interestingly, several file-sharing clients downloaded benign encrypted files after IceFire had encrypted the file server’s shared folders. Despite the attack on the server, clients were still able to download files from the encrypted server.”
At the time of writing, IceFire has reportedly impacted victims in Turkey, Iran, Pakistan and the United Arab Emirates (UAE). The Linux variants observed by SentinelOne were detected by none of the 61 VirusTotal engines.
“This evolution for IceFire fortifies that ransomware targeting Linux continues to grow in popularity through 2023,” Delamotte added. “While the groundwork was laid in 2021, the Linux ransomware trend accelerated in 2022 when illustrious groups added Linux encryptors to their arsenal, including the likes of BlackBasta, Hive, Qilin, Vice Society (aka HelloKitty) and others.”
Ransomware is not the only form of malware increasingly targeting the Linux OS. In December 2022, Trend Micro observed threat actors using the Chaos RAT to improve the efficiency of cryptocurrency mining attacks against Linux systems.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/icefire-ransomware-targets-linux/