Security researchers at SentinelLabs have reported that the IceFire ransomware operation has expanded their campaign with a new dedicated encryptor that targets Linux systems. The modification to also include a Linux encryptor aligns with a shift that has also been seen from other ransomware groups over the past two years. The researchers reported that over the last few weeks, the operators have breached numerous media and entertainment organizations around the world.
When executed, IceFire ransomware encrypts files and appends the “.ifire” extension to the file name. Following this, the ransomware deletes itself to cover its tracks. The ransomware only encrypts specific files on Linux hosts, avoiding files and paths that could lead to a complete system shutdown. To deploy IceFire, the operators are exploiting a deserialization vulnerability in the IBM Aspera Faspex file-sharing software (CVE-2022-47986) as a means of initial access. The vulnerability was initially discovered in January and has been patched since February 17.