Researchers at Russian antivirus company Doctor Web have discovered a Linux ransomware that has already infected tens of users. The Linux ransomware is launched as a. a. daemon and deletes the original files, subsequently, the RSA key is used to store AES keys used to encrypt files. It has been estimated that tens of. users have already fallen victim to this Linux ransomware. Once the ransom is paid the files are decrypted using a private RSA key that retrieves the. AES key from encrypted files.”]
Source: http://securityaffairs.co/wordpress/41787/cyber-crime/linux-ransomware.html

