Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On June 10, South Korean web hosting company NAYANA was hit by Erebus ransomware ... infecting 153 Linux servers and over 3,400 business websites the company hosts.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
As for how this Linux ransomware arrives, we can only infer that Erebus may have possibly leveraged vulnerabilities or a local Linux exploit. For instance, based on open-source intelligence, NAYANA’s website runs on Linux kernel 2.6.24.2... Security flaws like DIRTY COW ... can provide attackers root access to vulnerable Linux systems.
Erebus takes this up a notch; each file encrypted by Erebus will have this format... The file is first scrambled with RC4 encryption in 500kB blocks... The AES key is again encrypted using RSA-2048 algorithm... Ongoing analysis indicates that decryption is not possible without getting hold of the RSA keys.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux-targeting ransomware that encrypts files on web servers, especially website data and MySQL-related files, using layered RC4, AES, and RSA-2048 encryption and demanding Bitcoin ransom for decryption.
Ransomware that uses a UAC bypass by hijacking the .msc file association, elevates via eventvwr.exe, downloads a Tor client to reach its C2/payment site, encrypts targeted files with AES, renames extensions using ROT-23, deletes Volume Shadow Copies, and drops README.html ransom notes demanding about 0.085 BTC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.