Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Junglesec Ransomware - 9 Linux VMs are affected (Backup your data) - Ryzen 7000

2

Comments

  • ShakibShakib Member, Patron Provider

    This is what we got on hands.

    Thanked by 1fatchan
  • NeoonNeoon Community Contributor, Veteran

    At least he is directly honest not like GreencloudVPS

  • ShakibShakib Member, Patron Provider

    So Rack911 couldn't help. Every second file is encrypted.

    Have to reinstall this node.

    Already started securing and disabling all IPMI completely.

  • Excited for a round of ransomware-themed Black Friday deals from @Shakib!

    sale ransom letters

  • @Neoon said:
    At least he is directly honest not like GreencloudVPS

    yeah how they handled that incident killed any desire i had to use them

  • ShakibShakib Member, Patron Provider

    So one of my client wanted to pay for getting his VM decrypted.

    Might be an option if the data is very important.

  • Better backup yourself. Data is yours and can't rely on provider.

    Thanked by 1Shakib
  • @Shakib said:
    So one of my client wanted to pay for getting his VM decrypted.

    Might be an option if the data is very important.

    Pay.. who? Because if junglesec iirc it's dead and no one gives a fuck and/or give you keys

  • @Shakib said:

    Just found out one of our node is affected by Junglesec Ransomware and as per my count 9 Linux VMs were affected and Windows VMs are still safe from it (probably).

    Direct and straight forward communication and status update.
    Respect @Shakib

    Thanked by 2Shakib yoursunny
  • ShakibShakib Member, Patron Provider

    @JabJab said:

    @Shakib said:
    So one of my client wanted to pay for getting his VM decrypted.

    Might be an option if the data is very important.

    Pay.. who? Because if junglesec iirc it's dead and no one gives a fuck and/or give you keys

    Actually I am getting replies from the attacker. He wouldn't decrypt the whole hostnode for anything less than what mentioned but seems to be willing to decrypt one or two important VM for a few hundred bucks.

    And obviously I am asking him for future assurances as well while also pulling off Ethernet cables from our IPMI ports.

  • AdvinAdvin Member, Host Rep
    edited November 2024

    It’d be interesting to know the BMC version that was used here. I ordered an ARR B650D4U to see if I could poke around and find anything. Were simple/default passwords used?

    Thanked by 1Shakib
  • AdvinAdvin Member, Host Rep

    @Shakib said:

    @JabJab said:

    @Shakib said:
    So one of my client wanted to pay for getting his VM decrypted.

    Might be an option if the data is very important.

    Pay.. who? Because if junglesec iirc it's dead and no one gives a fuck and/or give you keys

    Actually I am getting replies from the attacker. He wouldn't decrypt the whole hostnode for anything less than what mentioned but seems to be willing to decrypt one or two important VM for a few hundred bucks.

    And obviously I am asking him for future assurances as well while also pulling off Ethernet cables from our IPMI ports.

    It’s not worth negotiating. It’s unlikely that they’ll actually decrypt your data and it’s most likely a scam.

    Thanked by 2Shakib yoursunny
  • ShakibShakib Member, Patron Provider

    @Advin said:
    It’d be interesting to know the BMC version that was used here. I ordered an ARR B650D4U to see if I could poke around and find anything. Were simple/default passwords used?

    BMC Firmware Version 4.10.00
    BIOS Firmware Version 3.11
    PSP Firmware Version 00.2B.00.4F
    Microcode Version 0a601203

    @Advin said:

    @Shakib said:

    @JabJab said:

    @Shakib said:
    So one of my client wanted to pay for getting his VM decrypted.

    Might be an option if the data is very important.

    Pay.. who? Because if junglesec iirc it's dead and no one gives a fuck and/or give you keys

    Actually I am getting replies from the attacker. He wouldn't decrypt the whole hostnode for anything less than what mentioned but seems to be willing to decrypt one or two important VM for a few hundred bucks.

    And obviously I am asking him for future assurances as well while also pulling off Ethernet cables from our IPMI ports.

    It’s not worth negotiating. It’s unlikely that they’ll actually decrypt your data and it’s most likely a scam.

    Let's see.

    Thanked by 1vpsGOD
  • truemagictruemagic Member
    edited November 2024

    Do keep us posted. Maybe best to send in few bucks to get a file (<5mb) decrypted before proceed further.

    Thanked by 2Shakib ebietsy
  • It would be nice if mods could pin a post urging all providers to check if their IPMI is public and take action immediately.

  • plumbergplumberg Veteran, Megathread Squad

    @Shakib - did you notice any of your Windows "nodes" affected with this?

    Thanked by 1Shakib
  • so, when do you offer flash sales of ultra cheap servers? i trust your service and looking for people jumping off the boat

  • @DeadlyChemist said:
    so, when do you offer flash sales of ultra cheap servers? i trust your service and looking for people jumping off the boat

    I am with @Shakib for 3+ years and plan to continue.

    Thanked by 1Shakib
  • ShakibShakib Member, Patron Provider

    @plumberg said:
    @Shakib - did you notice any of your Windows "nodes" affected with this?

    No. Windows VMs aren't affected by ccrypto that was used to encrypt. (90% sure)

    Also if anyone is interested, this is what the attacker told me,

    Ok by memory VPS was mounted to /mnt/ (from /dev/zvol/)
    
    The only way is to mount the VPS from /dev/zvol to a mountpoint like 
    /mnt/jungle and execute
    
    ccrypt -d -r /mnt/jungle
    
    which will decrypt all files of the VPS
    
    I don't have access to the server anymore, you can run 
    /usr/bin/systemd-host which is my remote shell if you want I proceed and 
    delete the binary once I'm done
    
    Thanked by 1plumberg
  • ShakibShakib Member, Patron Provider

    @dev_vps said:

    @DeadlyChemist said:
    so, when do you offer flash sales of ultra cheap servers? i trust your service and looking for people jumping off the boat

    I am with @Shakib for 3+ years and plan to continue.

    <3 <3 <3

    You should still back your data up.

    And we might have found a solution to keep our nodes up even during 300+ load average. A new code was implemented to most of our Ryzen nodes along with additional security features.

    We couldn't find any vulnerabilities on our other nodes so far but I do suspect something. Will keep monitoring.

  • ShakibShakib Member, Patron Provider

    It seems one VM that was using netboot.xyz Debian OS might have survived the attack.

    Only the client can confirm.

  • I think that was me?

    How do I know if i survived the attack?

    I remember A while ago I messed up somethin and the only way to load and os was using netboot. So I think I installed using that.

    Thanked by 1Shakib
  • @Shakib said: Only the client can confirm.

    I'm running netboot installed Debian and got a ticket asking me to check my VPS. When I checked it out it was at an initramfs prompt with the filesystem needing to be fsck'd. I ran the fsck and let it fix up whatever it wanted (I don't have any data I care about). Unfortunately after the filesystem mounted I see the same junglesec files all over, so its toast.

    Thanked by 1Shakib
  • @Shakib

    I have a node on Ryzen 7000 but I don't think I am affected. Still able to login to KASM. Are there multiple Ryzen 7000 nodes?

    Thanked by 1Shakib
  • zGatozGato Member
    edited November 2024

    @shajeeafzal said:
    @Shakib

    I have a node on Ryzen 7000 but I don't think I am affected. Still able to login to KASM. Are there multiple Ryzen 7000 nodes?

    True. May we know the VPS node name(s) that are affected so we can check in the panel on which one we are?
    Haven't received any ticket and VM seems fine.

    Thanked by 2Xrmaddness Shakib
  • @zGato said:

    True. May we know the VPS node name(s) that are affected so we can check in the panel on which one we are?
    Haven't received and ticket and VM seems fine.

    Same, I got the initial email, but nothing else since. I assume I'm fine?

    Thanked by 1Shakib
  • Regards for being upfront about this terrible occurence, and not users finding the opposite like at other hosts.

    Thanked by 1Shakib
  • PureVoltagePureVoltage Member, Patron Provider

    If ipmi is on the public network you will be hacked at some point. Sm systems are the worst but many others who use the same are not very secure. I would suggest anyone with a public facing ipmi to take backups and ask to at the least whitelist a specific ip only to access it.

    Ideally all providers should never give out a public ipmi address. Even for our single server and plenty of full rack colo customers we offer to have their systems on our private vpn.

  • ShakibShakib Member, Patron Provider

    @HackedServer said:

    @Shakib said: Only the client can confirm.

    I'm running netboot installed Debian and got a ticket asking me to check my VPS. When I checked it out it was at an initramfs prompt with the filesystem needing to be fsck'd. I ran the fsck and let it fix up whatever it wanted (I don't have any data I care about). Unfortunately after the filesystem mounted I see the same junglesec files all over, so its toast.

    I have a backup copy that I could restore on another node if you want to give it another shot.

  • ShakibShakib Member, Patron Provider

    @shajeeafzal said:
    @Shakib

    I have a node on Ryzen 7000 but I don't think I am affected. Still able to login to KASM. Are there multiple Ryzen 7000 nodes?

    Only Neptune node with 9 Linux VM was affected so far.

    I suspect one more IPMI could be compromised. Just monitoring it for now.

Sign In or Register to comment.