Company
Date Published
Author
-
Word count
3056
Language
English
Hacker News points
None

Summary

TellYouThePass ransomware, initially discovered in 2019, has resurfaced with new samples written in Golang, highlighting its evolution in targeting both Windows and Linux systems. This ransomware is associated with the Log4Shell vulnerability and uses RSA-1024 and AES-256 encryption to lock files, demanding a ransom in bitcoin for decryption. The malware is noted for its cross-platform capabilities due to Golang's flexibility, which allows developers to compile the same codebase for multiple operating systems. It specifically targets popular media and file extensions while excluding certain directories from encryption. CrowdStrike's Falcon platform leverages cloud-based and on-sensor machine learning to detect and protect against this ransomware, showcasing its ability to handle sophisticated threats by using behavioral detection and indicators of attack (IOAs). This protection extends to various environments, ensuring comprehensive security against the evolving threat landscape.