Researchers observed a new Python-based ransomware attack aimed at misconfigured, internet-exposed Jupyter Notebook environments, marking an unusual shift from the cryptojacking activity more commonly seen against these systems. In Aqua Security's honeypot, an attacker accessed an exposed Jupyter instance, opened a terminal session, downloaded malicious tools, and manually assembled a ransomware script designed to copy and encrypt files, delete the original unencrypted data, and then remove itself to reduce forensic evidence.
The attack did not fully complete in the monitored environment, and no ransom note was recovered, suggesting the operator may have been testing tooling or was interrupted during execution. Researchers said artifacts from the intrusion indicate the actor may be linked to earlier campaigns targeting Jupyter servers for illicit cryptocurrency mining and may be Russian-speaking, underscoring the risk that poorly secured notebook servers can be turned into high-impact ransomware targets if they are exposed to the internet without hardening and reliable backups.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Aqua Security's Team Nautilus observed a new Python-based ransomware strain targeting a misconfigured, internet-exposed Jupyter Notebook instance in a honeypot. The attacker accessed the environment, opened a terminal, downloaded tools, and manually created a Python ransomware script, but the attack did not fully complete and no ransom note was recovered.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.