A ransomware strain dubbed NextCry was found encrypting data on self-hosted Nextcloud Linux servers, with victims reporting that files in the platform’s data directory were locked and no free decryptor was available. Researchers said the malware was a Python-based payload packaged as a Linux ELF binary with pyInstaller, using AES-256 for file encryption and an embedded RSA-2048 public key to protect the encryption key. The malware reportedly parsed Nextcloud’s config.php file to locate the correct data directory and also deleted folders that could aid recovery.
Investigators linked the intrusions to exploitation of CVE-2019-11043, a remote code execution flaw in NGINX/PHP-FPM configurations commonly used with some Nextcloud deployments, rather than to a vulnerability in Nextcloud itself. Nextcloud had separately issued an urgent warning about the NGINX/PHP-FPM issue, underscoring that exposed servers using affected default configurations were at risk of compromise and subsequent ransomware deployment.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Nextcloud issued an urgent security alert about CVE-2019-11043, a remote code execution flaw in PHP-FPM affecting certain default NGINX-based Nextcloud deployments. It advised administrators to update PHP packages and NGINX configuration files.
After investigating the incidents, Nextcloud said it was confident the attacker was exploiting the nginx+php-fpm issue covered by its advisory rather than a vulnerability in Nextcloud itself. The reporting also noted that a public exploit for CVE-2019-11043 existed and had been used to compromise servers.
Analysis showed NextCry was a Python script compiled into a Linux ELF binary with pyInstaller that specifically locates Nextcloud's data directory via config.php, deletes some restorable folders, and encrypts files using AES-256 with the key protected by an embedded RSA-2048 public key. At the time of reporting, no free decryptor was available.
A new ransomware strain called NextCry was identified targeting Nextcloud file sync and share servers, with multiple victims reporting infections. Victims reported encrypted files, SSH lockout, and in one case roughly half of files were encrypted before the server was taken offline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.