Unpatched WS_FTP servers are being targeted to spread ransomware


Organizations that have not yet patched their WS_FTP Server instances are now being targeted by ransomware. This is according to a new report from cybersecurity experts Sophos X-Ops, who recently thwarted one such attempt against one of their clients.
A relatively unknown threat actor going by the name Reichsadler Cybercrime Group apparently tried to deploy the LockBit 3.0 builder, stolen in September 2022, against an unnamed company.
“The ransomware actors didn’t wait long to abuse the recently reported vulnerability in WS_FTP Server software,” the researchers said. “Even though Progress Software released a fix for this vulnerability in September 2023, not all of the servers have been patched. Sophos X-Ops observed unsuccessful attempts to deploy ransomware through the unpatched services.”
Automated attacks
In the attack, Reichsadler tried to gain elevated privileges using the open-source tool called GodPotato. Even though the attempt failed, they still left a ransom note, demanding $500 in cryptocurrency. This, the researchers speculate, means that the attackers are either inexperienced, or they automated an attack in which they targeted numerous companies (or both). A Shodan listing showed almost 2,000 vulnerable instances, BleepingComputer reported.
Two weeks ago, Progress (the company behind WS_FTP) published a security advisory in which it detailed fixes for a total of eight vulnerabilities. Two are deemed critical. One is tracked as CVE-2023-40044 (severity rating 10/10), while the other is tracked as CVE-2023-42657 (9.9/10). These vulnerabilities allow threat actors to run a range of malicious activities, including remote code execution.
“Attackers could also escape the context of the WS_FTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system,” Progress said in the advisory.
Prior to the WS_FTP Server news, Progress made headlines after its other product, MOVEit, was at the center of a data theft fiasco that affected more than 2,500 organizations and more than 64 million individuals.
Via BleepingComputer
More from TechRadar Pro
Organizations that have not yet patched their WS_FTP Server instances are now being targeted by ransomware. This is according to a new report from cybersecurity experts Sophos X-Ops, who recently thwarted one such attempt against one of their clients. A relatively unknown threat actor going by the name Reichsadler Cybercrime…
Recent Posts
- Netflix drops an uneasy new teaser for You season 5, and I can’t help but laugh as killer Casanova Joe calls himself ‘the luckiest guy in New York’
- Popular Android financial help app is actually dangerous malware
- Our Favorite Internal SSD Is on Sale Right Now
- Tesla reportedly launches FSD in China — or has it?
- Clicks is finally releasing its keyboard add-on for some Android phones
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010