Skip to content

Ransomware malware targeting Linux Desktop users spotted in the wild

github.com/evilsocket
12 pointsgus_2 comments
On HN

Comments

not linux, but Go packages.

gus_OP

The campaign is using Go packages just as a mechanism to download a ransomware for Linux systems, and it specifically checks if the Documents/ directory exists for the current user. If it doesn't exist it does nothing.

That's probably why the malware sandboxes are not detecting the outbound connections and the encrypting activity.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.