First Python Ransomware Attack Targeting Jupyter Notebook
ID: e4e45be5-51e7-591e-86f0-2f3d42f42641
STIX ID: report--e4e45be5-51e7-591e-86f0-2f3d42f42641
Feed Name: Aqua Security Blog
Threat Score
Team Nautilus observed and analyzed a Python-based ransomware attack against misconfigured, internet-exposed Jupyter Notebook servers: the attacker uploaded tools, created and executed a Python encryptor (cpt.py) that encrypts files and self-deletes, leaving no ransom note; detections via Tracee captured file drop and execution events and indicators include a characteristic dropped file named 'f1gl6i6z'.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
