The new threat is written in PHP and encrypts all files in Web server directories A new malicious program that encrypts files on Web servers has affected at least 100 websites over the past few weeks, signaling a new trend in ransomware development.The program, which is written in PHP, is called CTB-Locker, a name also used by one of the most widespread ransomware programs for Windows computers. It’s not clear though if there’s a relationship between this new Web-based ransomware and the Windows version.Once installed on a Web server, the program replaces the site’s index.php and creates a directory called Crypt that contains additional PHP files. It starts to encrypt all the files in the server’s Web directory when it receives a specifically crafted request from an attacker.After the encryption process is complete, the website’s home page will display a message asking for a payment to be made in bitcoin. One of the first attacks with this Web-based version of CTB-Locker was reported on Feb. 12 when the website of the British Association for Counselling and Psychotherapy fell victim to it.It wasn’t immediately clear at the time whether the website was affected by a real ransomware attack or if it was just an attempt to scare the website owners. Some people were understandably skeptical because the CTB-Locker name had previously only been associated with Windows ransomware. Researchers from Stormshield, a subsidiary of Airbus Defence and Space, have since managed to obtain a full copy of the malicious code from another affected website. In fact they they found 102 websites that have been infected with this Web-based ransomware so far.It’s not yet clear how the attackers gained access to those websites in order to install CTB-Locker. Blaming a specific vulnerability in a popular content management system (CMS) like WordPress is hard, because some of the affected websites did not use a CMS, the Stormshield researchers said in a blog post Friday.“The infected hosts run both Linux and Windows and the majority of them (73%) host an Exim service (SMTP server),” they said. “Some of them are vulnerable to ShellShock, but without a deep access on victims’ servers, it is difficult to understand how this ransomware infected hosts.”Most of the affected websites also had a password-protected Web shell installed. This is a type of backdoor program that attackers install on Web servers once they’ve gained unauthorized access to them.CTB-Locker is not the first ransomware to target websites. In November, researchers discovered a similar threat dubbed Linux.Encoder.1, but that program appeared to be experimental and had cryptographic flaws that allowed researchers to create a decryption tool.It’s likely that Linux.Encoder.1 served as inspiration for other ransomware creators, showing that such attacks against Web servers are viable. As such, CTB-Locker will probably not be the last ransomware program to encrypt websites. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe