Linux systems are receiving ransomware and cryptojacking attacks
Since Linux is widely used in server structures and large enterprises, it has become a very lucrative target for ransomware. One of the maxims of cyberattacks is that it compensates the time to execute a cyberattack and handle the ransoms, that is why large companies with sensitive data are very juicy targets, and therefore if the use of Linux is extended in these companies, to create ransomware for Linux.
The popularity of Linux-based services in cloud and digital infrastructure sectors has made them a target for ransomware attacks, as reported VMware. Added to this is that a lot of digital protection software is based on Windows, so Linux is de facto much more unprotected compared to its popularity and importance factor.
Linux is no longer safe from ransomware
The VMware report, based on its real-time big data, event stream processing, static, dynamic and behavioral analytics, and machine learning data; claims that the ransomware has evolved to target host images used for handling workloads in virtualized environments. It means that ransomware attacks are more focused on cloud services seen their potential and the sensitive information they handle.
VMWare also warns that multi-cloud infrastructure is being abused to mine cryptocurrencies for attackers. Cryptojacking is spreading and causing cryptocurrency to be mined for hackers. And because it doesn't completely disrupt the operations of cloud environments, it's much harder to detect if a computer is infected.
There is also the growing problem of Cobalt Strike y Vermillion Strike, commercial penetration testing tools and for redhats for Windows and Linux. They are not designed to be malicious, but they can be used to break into a compromised system and give a cracker partial control of the machine. VMware concludes after its investigations that more than half of Cobalt Strike users may be cybercriminals.
Source: TechRadar