logo

First Python Ransomware Attack Targeting Jupyter Notebook

ID: e4e45be5-51e7-591e-86f0-2f3d42f42641

STIX ID: report--e4e45be5-51e7-591e-86f0-2f3d42f42641

Feed Name: Aqua Security Blog

Threat Score
65/100

Date Published: 2022-03-29

Date Updated: 2026-04-26

...
...

Team Nautilus observed and analyzed a Python-based ransomware attack against misconfigured, internet-exposed Jupyter Notebook servers: the attacker uploaded tools, created and executed a Python encryptor (cpt.py) that encrypts files and self-deletes, leaving no ransom note; detections via Tracee captured file drop and execution events and indicators include a characteristic dropped file named 'f1gl6i6z'.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.