• Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
Tutorial News Comments FAQ Related Articles

‘NamPoHyu Virus’ ransomware target vulnerable Samba servers

{{postValue.id}}

There is a new ransomware that haunts the vulnerable Samba servers and it is called ‘NamPoHyu Virus'.

The ransomware is directly launched on the Samba servers by brute forcing the passwords, a move which is unusual from running executables on a victim’s computer

It was once called MegaLocker Virus and now it remotely encrypts the files and then leaves a ransom note.

Shodan, the search engine, has found some 500,000 accessible Samba servers across the globe. This indicates that this ransomware infection can be massive if the attackers gain access to these vulnerable Samba servers.

The ransomware was first identified in March 2019 after users complained that their NAS storage devices were suddenly encrypted by new ransomware called MegaLocker virus.

After the encryption is completed it leaves those encrypted files with .crypted extension and thereby leaving the ransom note named !DECRYPT_INSTRUCTION.TXT.

The ransom note contains instructions to contact alexshkipper@mail[.]ru. The note asks the prospective victim to send a photo from birthday, holiday, hobbies or some other personal event. If the victim is a single user, then the ransom amount stands at $250 otherwise it would be $1000 for companies.

According to Bleeping Computer, its name was changed to the current 'NamPoHyu Virus' since April 2019.

Tags:
connor
Author: 

Comments ( 0 )

No comments available

Add a comment
{{postCtrl.cmtErrMsg}}

Frequently asked questions ( 0 )

No questions available

Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Sebastian ?
How to change non required to required field in SuiteCRM Custom/Default Modules

How to change not required to the required field in SuiteCRM Custom/Default Modules?

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.