top | item 43336153

Ransomware malware targeting Linux Desktop users spotted in the wild

12 points| gus_ | 11 months ago |github.com

2 comments

order

asdffdasy|11 months ago

not linux, but Go packages.

gus_|11 months ago

The campaign is using Go packages just as a mechanism to download a ransomware for Linux systems, and it specifically checks if the Documents/ directory exists for the current user. If it doesn't exist it does nothing.

That's probably why the malware sandboxes are not detecting the outbound connections and the encrypting activity.