{"id":42414,"date":"2021-06-17T00:00:00","date_gmt":"2021-06-17T00:00:00","guid":{"rendered":"https:\/\/www.trendmicro.com\/en_us\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions.html"},"modified":"2021-06-17T00:00:00","modified_gmt":"2021-06-17T00:00:00","slug":"bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/","title":{"rendered":"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%200-DarkRad-banner.png\"><!-- Begin mPulse library --><!-- END mPulse library --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"We investigate how certain hacking tools are used to move laterally on victims\u2019 networks to deploy ransomware. These tools contain reconnaissance\/spreader scripts, exploits for Red Hat and CentOS, binary injectors, and more. In this blog, we focus on analyzing the worm and ransomware script. \"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"endpoints,ransomware,research,articles, news, reports\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2021-06-17\"> <meta property=\"article:tag\" content=\"ransomware\"> <meta property=\"article:section\" content=\"research\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions.html\"> <title>Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions.html\"><br \/>\n<meta property=\"og:title\" content=\"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions\"><br \/>\n<meta property=\"og:description\" content=\"We investigate how certain hacking tools are used to move laterally on victims\u2019 networks to deploy ransomware. These tools contain reconnaissance\/spreader scripts, exploits for Red Hat and CentOS, binary injectors, and more. In this blog, we focus on analyzing the worm and ransomware script. \"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%200-DarkRad-banner.png\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions\"><br \/>\n<meta name=\"twitter:description\" content=\"We investigate how certain hacking tools are used to move laterally on victims\u2019 networks to deploy ransomware. These tools contain reconnaissance\/spreader scripts, exploits for Red Hat and CentOS, binary injectors, and more. In this blog, we focus on analyzing the worm and ransomware script. \"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%200-DarkRad-banner.png\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"51.45205888947\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1392333950\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"10.298936170213\">\n<div class=\"article-details\" role=\"heading\" readability=\"40.214893617021\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Ransomware<\/p>\n<p class=\"article-details__description\">We investigate how certain hacking tools are used to move laterally on victims\u2019 networks to deploy ransomware. These tools contain reconnaissance\/spreader scripts, exploits for Red Hat and CentOS, binary injectors, and more. In this blog, we focus on analyzing the worm and ransomware script. <\/p>\n<p class=\"article-details__author-by\">By: Aliakbar Zahravi <time class=\"article-details__date\">June 17, 2021<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"39.322033898305\">\n<div readability=\"24.576271186441\">\n<p>A recently discovered Bash ransomware piqued our interest in multiple ways. Upon investigating, we found that the attack chain is fully implemented as a bash script, but it also seems that the scripts are still under development. Most components of this attack mainly target Red Hat and CentOS Linux distributions; however, in some scripts Debian-based Linux distributions are included as well. The worm and ransomware scripts also use the API of the messaging application Telegram for command-and-control (C&amp;C) communication. We also found that most components of this attack have very low detection numbers in Virus Total. The hack tools URL with the ransomware information was initially reported by Twitter user <a href=\"https:\/\/twitter.com\/r3dbu7z?lang=en\" target=\"_blank\" rel=\"noopener\">@r3dbU7z<\/a>.&nbsp;<\/p>\n<p>In the next sections of this blog, we analyze the content of the \u201capi_attack\/\u201d directory, which contains the Secure Shell (SSH) worm and ransomware script.<\/p>\n<p><span class=\"body-subhead-title\">Attack preview<\/span><\/p>\n<p>The following is a list and overview of the hacking tools. We\u2019ve observed that some of these scripts are based on open-source code. For example, binaryinject1.so is a modified version of a rootkit called \u201c<a href=\"https:\/\/github.com\/gianlucaborello\/libprocesshider\" target=\"_blank\" rel=\"noopener\">libprocesshider<\/a>\u201d that hides a process under Linux using the ld preloader and \u201cpwd.c\u201d (\u201cCVE-2017-1000253.c\u201d), which is a publicly available exploit for CentOS 7 kernel versions 3.10.0-514.21.2.el7.x86_64 and 3.10.0-514.26.1.el7.x86_64.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%201-DarkRad-hacktools.png\" alt=\"Figure 1. Threat actor\u2019s hack tools directory\"><figcaption>Figure 1. Threat actor\u2019s hack tools directory<\/figcaption><\/figure>\n<\/p><\/div>\n<div>\n<div class=\"richText\" readability=\"34\">\n<div readability=\"13\">\n<p>Among all these tools, the content of \u201capi_attack\/\u201d grabbed our attention. The \u201capi_attack\u201d directory contains the various versions of the Bash ransomware that we named DarkRadiation, as well as the SSH worm that is responsible for spreading this ransomware. The \u201cSupermicro_cr_third\u201d script in this directory seems to be the most complete version of the ransomware. This script is obfuscated with an open-source tool called \u201cnode-bash-obfuscate\u201d, which is a Node.js CLI tool and library to obfuscate bash scripts.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%202a-DarkRad-hacktools-api.png\" alt=\"Figure 2. Threat actor\u2019s hack tools directory for \/api_attack\"><figcaption>Figure 2. Threat actor\u2019s hack tools directory for \/api_attack<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%203a-DarkRad-hosting%20directory.png\" alt=\"Figure 3. Threat actor\u2019s malware hosting directory\"><figcaption>Figure 3. Threat actor\u2019s malware hosting directory<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p>Most scripts in this directory have zero detections in Virus Total:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%204-DarkRad-VT%20results.png\" alt=\"Figure 4. Virus Total results\"><figcaption>Figure 4. Virus Total results<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"35\">\n<div readability=\"15\">\n<p><span class=\"body-subhead-title\">Malware analysis<\/span><\/p>\n<p>In this section, we take a closer look at worm and ransomware scripts.<\/p>\n<p><b>SSH Worm<\/b><\/p>\n<p>The \u201cdownloader.sh\u201d is an SSH worm that accepts base64-encoded configuration credentials as an argument. These credentials would either be dumped by the attacker after the initial foothold on a victim\u2019s systems or used as a brute-force list that targets systems with weak password protection. Essentially, the malware checks if the given configuration is set to use an SSH password attack or an SSH key base attack \u2014 it can also test SSH passwords or SSH keys against the targeted IP address. Upon successful connection, the malware downloads and executes ransomware on a remote system. The following is a format credential input to the script after decoding:&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%204a-DarkRad-credinput.png\" alt=\"DarkRad credential input to the script after decoding\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p>The following code snippet demonstrates this behavior of the malware:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%205-DarkRad-worm%20entry.png\" alt=\"Figure 5. Worm entry function\"><figcaption>Figure 5. Worm entry function<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"36.5\">\n<div readability=\"18\">\n<p>The check_ssh_connection function returns code:0 for a successful connection, code:254 for the ping error, and code:255 for SSH connection error both with password and key. The malware uses the sshpass utility to use non-interactive SSH password authentication.<\/p>\n<p>In the case of SSH inline password, the malware sets sshpass parameter \u201cpasswordauthentication=yes\u201d. It stores the ransomware script in the \u201c\/usr\/share\/man\/man8\/\u201d directory and executes it. To keep the process running in case the SSH session is terminated, the malware uses screen session and nohup command.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%206-DarkRad-worm%20recon.png\" alt=\"Figure 6. Worm reconnaissance and spreading functionality\"><figcaption>Figure 6. Worm reconnaissance and spreading functionality<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The malware obtains an encryption password ($crypt_pass) via an API call to its C&amp;C server and passes it to the supermicro_cr.gz script.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%207-DarkRad-encryptkey.png\" alt=\"Figure 7. Request for encryption key\"><figcaption>Figure 7. Request for encryption key<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>The malware has an install_tools function to download and install necessary utilities on an infected system in case they are not already installed. Based on this function, we can see that the worm only downloads and installs prerequisite packages for CentOS- or RHEL-based Linux distribution because it uses only the Yellowdog Updater, Modified (YUM) package manager. Some other hacking tools as well as the DarkRadiation ransomware variants use only YUM to download and install prerequisite packages.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%208-DarkRad-packageinstall.png\" alt=\"Figure 8. Prerequisite package installation\"><figcaption>Figure 8. Prerequisite package installation<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>Finally, the malware reports the scanning\/spreading result to the attacker via Telegram\u2019s API:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%209-DarkRad-Telegram.png\" alt=\"Figure 9. The malware sends execution status to the attacker's Telegram channel.\"><figcaption>Figure 9. The malware sends execution status to the attacker&#8217;s Telegram channel.<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"44.897980501393\">\n<div readability=\"35.523676880223\">\n<p><b>The DarkRadiation Ransomware<\/b><\/p>\n<p>In the previous section, we talked about the SSH worm script that received the credential configuration as a base64 parameter and used it against target systems to download and execute the ransomware.&nbsp;<\/p>\n<p>Looking at various iterations of the ransomware in this section, we investigate the script called \u201csupermicro_cr_third\u201d, which seems like the latest version. The ransomware is written in bash script and targets Red Hat\/CentOS and Debian Linux distributions. The malware uses OpenSSL\u2019s AES algorithm with CBC mode to encrypt files in various directories. It also uses Telegram\u2019s API to send an infection status to the threat actor(s).&nbsp;<\/p>\n<p>We observed that this script is heavily under development, and various versions of this ransomware are all similar with only minor changes. Some functions are commented by the malware author, while some functions are not used (dead code) in some cases. In this section, we discuss the details of how this ransomware works.<\/p>\n<p>The script is obfuscated with an open-source tool called \u201c<a href=\"https:\/\/github.com\/willshiao\/node-bash-obfuscate\" target=\"_blank\" rel=\"noopener\">node-bash-obfuscate<\/a>,\u201d which is a Node.js CLI tool and library to obfuscate bash scripts. This tool divides the bash script into chunks and then assigns a variable name to each chunk and replaces the original script with variable references, essentially scrambling the original script.<\/p>\n<p>The following code snippet demonstrates the use of this script to obfuscate a bash script:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2010-DarkRad-bashobfuscate.png\" alt=\"Figure 10. node-bash-obfuscate options\"><figcaption>Figure 10. node-bash-obfuscate options<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2011-DarkRad-nodesample.png\" alt=\"Figure 11. node-bash-obfuscate sample output\"><figcaption>Figure 11. node-bash-obfuscate sample output<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p>supermicro_cr_third analysis:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2012-DarkRad-supermicro.png\" alt=\"Figure 12. A supermicro_cr_third obfuscated script\"><figcaption>Figure 12. A supermicro_cr_third obfuscated script<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>Upon execution, the malware checks if it executed as root; if it did not, it displays \u201cPlease run as root\u201d message, removes itself, and exits.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2013-DarkRad-supermicrothree.png\" alt=\"Figure 13. supermicro_cr_third main function\"><figcaption>Figure 13. supermicro_cr_third main function<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2014-DarkRad-scriptroot.png\" alt=\"Figure 14. Checking if script run as root\"><figcaption>Figure 14. Checking if script run as root<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>It then checks if curl and OpenSSL are installed; if they are not, the malware then downloads and installs them.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2015-DarkRad-packinstall.png\" alt=\"Figure 15. A prerequisite package installation in another version\"><figcaption>Figure 15. A prerequisite package installation in another version<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2016-DarkRad-prereqpackage.png\" alt=\"Figure 16. A prerequisite package installation in supermicro_cr_third\"><figcaption>Figure 16. A prerequisite package installation in supermicro_cr_third<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>The bot_who function is a bash script that takes a snapshot of the users that are currently logged into a Unix computer system using the \u201cwho\u201d command. It stores the result in a hidden file called (\u201c\/tmp\/.ccw\u201d). Afterward, every five seconds it again executes the \u201cwho\u201d command and checks the output \u201c.ccw\u201d file. If they are not equal (new user logging in), the malware sends a message to the attacker via Telegram\u2019s API:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2017-DarkRad-supermicro-bt.png\" alt=\"Figure 17. supermicro_bt script\"><figcaption>Figure 17. supermicro_bt script<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>Before the encryption process, the ransomware retrieves a list of all available users on an infected system by querying the &#8220;\/etc\/shadow&#8221; file. It overwrites all existing user passwords with \u201cmegapassword\u201d and deletes all existing users except \u201cferrum.\u201d After that, the malware creates a new user from its configuration section with username \u201cferrum\u201d and password \u201cMegPw0rD3\u201d. It executes &#8220;usermod &#8211;shell \/bin\/nologin&#8221; command to disable all existing shell users on an infected system:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2018-DarkRad-supermicro-config.png\" alt=\"Figure 18. supermicro_cr_third configuration\"><figcaption>Figure 18. supermicro_cr_third configuration<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2019-DarkRad-changeuserfunc.png\" alt=\"Figure 19. user_change function in supermicro_cr_third\"><figcaption>Figure 19. user_change function in supermicro_cr_third<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>Some ransomware variants attempt to delete all existing users except username \u201cferrum\u201d and \u201croot\u201d:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2020-DarkRad-userchangefunc.png\" alt=\"Figure 20. user_change function in crypt3.sh)\"><figcaption>Figure 20. user_change function in crypt3.sh)<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>It also checks if \u201c0.txt\u201d exists in the C&amp;C server. If it does not exist, the malware does not execute the encryption process and sleeps for 60 seconds, after which it tries again. It must be noted that wget will be invoked with \u201c&#8211;spider\u201d option to just check if \u201c0.txt\u201d exists in the given URL.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2021-DarkRad-loopTelegram.png\" alt=\"Figure 21. loop_wget_telegram function\"><figcaption>Figure 21. loop_wget_telegram function<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2022-DarkRad-checkattack.png\" alt=\"Figure 22. \u201c\/check_attack\u201d directory\"><figcaption>Figure 22. \u201c\/check_attack\u201d directory<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<div readability=\"9\">\n<p>For encryption, the ransomware uses OpenSSL\u2019s AES algorithm in CBC mode. The malware gets an encryption password through the command-line argument passed by the worm script:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2023-DarkRad-supermicro-threeconfig.png\" alt=\"Figure 23. supermicro_cr_third key configuration\"><figcaption>Figure 23. supermicro_cr_third key configuration<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>It is important to note that the encryption path can be different in other versions. Super_micro_third uses a separated script called (crypt_file.sh) for file encryption. However, other variants such as supermicro_cr do the file encryption by themselves. Also, it must be noted that the ransomware appends radioactive symbols (\u201c\u2622\u201d) as a file extension for an encrypted file.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2024-DarkRad-supermicro-encrypt.png\" alt=\"Figure 24. super_micro_third encryption process\"><figcaption>Figure 24. super_micro_third encryption process<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2025-DarkRad-supermicro-encryfunc.png\" alt=\"Figure 25. supermicro_cr encryption function\"><figcaption>Figure 25. supermicro_cr encryption function<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31\">\n<div readability=\"7\">\n<p>The malware sends the encryption status to the attacker via Telegram\u2019s API:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2026-DarkRad-Teleconfig.png\" alt=\"Figure 26. Telegram configuration\"><figcaption>Figure 26. Telegram configuration<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2026b-DarkRad-config.png\" alt=\"DarkRad- Telegram configuration 2\"> <\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The malware also stops and disables all running Docker containers on an infected system and creates a ransom note:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions\/Figure%2027-DarkRad-DR-ransomnote.png\" alt=\"Figure 27. Ransom note\"><figcaption>Figure 27. Ransom note<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"44.49860724234\">\n<div class=\"responsive-table-wrap\" readability=\"34.610027855153\">\n<p><span class=\"body-subhead-title\">Conclusion<\/span><\/p>\n<p>Overall, an adversary uses a variety of hacking tools to move laterally on victims\u2019 networks to deploy ransomware. These hacking tools contain reconnaissance\/spreader scripts, exploits for Red Hat and CentOS, binary injectors (<a href=\"https:\/\/github.com\/gianlucaborello\/libprocesshider\" target=\"_blank\" rel=\"noopener\">libprocesshider<\/a> rootkit), and more. However, most of the tools have very low detection numbers in Virus Total. It seems that some of the scripts are still in the development phase.&nbsp;<\/p>\n<p>There were other notable elements as well. The worm and ransomware scripts are able to communicate with the attacker via Telegram API and directly access the C&amp;C server. The ransomware can delete all users on an infected system (although in some variants it keeps the root user) and can create an account only for the attacker. As for file encryption, the ransomware uses OpenSSL\u2019s AES algorithm to encrypt either the file with specific extensions or all files at the given directory.&nbsp;<\/p>\n<p>In this blog, we focused on analyzing the worm and supermicro_tr_third ransomware script. We found that the ransomware was obfuscated with an open-source tool called &#8220;node-bash-obfuscate,&#8221; which is a Node.js CLI tool and library to obfuscate bash scripts. Hopefully, this can help with detection in case the attacker comes up with other ransomware variants using the same tool.<\/p>\n<p>Trend Micro has a multilayered cybersecurity platform that can help improve an organization\u2019s detection and response against the latest ransomware attacks and improve security teams\u2019 visibility. Visit the <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/detection-response.html\">Trend Micro Vision One\u2122<\/a> website for more information.<\/p>\n<p><span class=\"body-subhead-title\">Indicators of Compromise (IOCs)<\/span><\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\" width=\"100%\">\n<tbody readability=\"29\">\n<tr readability=\"2\">\n<td><b>Sha256<\/b><\/td>\n<td><b>Script name<\/b><\/td>\n<td><b>Trend Micro Detection Name<\/b><\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>d0d3743384e400568587d1bd4b768f7555cc13ad163f5b0c3ed66fdc2d29b810<\/td>\n<td>supermicro_cr<\/td>\n<td>Ransom.SH.DARKRADIATION.A<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>652ee7b470c393c1de1dfdcd8cb834ff0dd23c93646739f1f475f71a6c138edd<\/td>\n<td>supermicro_bt<\/td>\n<td>Trojan.SH.DARKRADIATION.A<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>9f99cf2bdf2e5dbd2ccc3c09ddcc2b4cba11a860b7e74c17a1cdea6910737b11<\/td>\n<td>supermicro_cr_third (obfuscated)<\/td>\n<td>Ransom.SH.DARKRADIATION.A<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>654d19620d48ff1f00a4d91566e705912d515c17d7615d0625f6b4ace80f8e3a<\/td>\n<td>supermicro_cr_third (deobfuscated)<\/td>\n<td>Ransom.SH.DARKRADIATION.D<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>79aee7a4459d49dc6dfebf1a45d32ccc3769a1e5c1f231777ced3769607ba9c1<\/td>\n<td>test.sh<\/td>\n<td>Trojan.SH.DARKRADIATION.A<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>da68dc9d5571ef4729adda86f5a21d3f4478ddbae2de937f34f57f450d8a3c76<\/td>\n<td>downloader.sh.save<\/td>\n<td>Trojan.SH.DARKRADIATION.A<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>3bab2947305c00df66cb4d6aaef006f10aca348c17aa2fd28e53363a08b7ec68<\/td>\n<td>downloader.sh<\/td>\n<td>Trojan.SH.DARKRADIATION.A<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>0243ac9f6148098de0b5f215c6e9802663284432492d29f7443a5dc36cb9aab5<\/td>\n<td>crypt3.sh<\/td>\n<td>Trojan.SH.DARKRADIATION.A<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>e380c4b48cec730db1e32cc6a5bea752549bf0b1fb5e7d4a20776ef4f39a8842<\/td>\n<td>crypt2_first.sh<\/td>\n<td>Ransom.SH.DARKRADIATION.A<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>fdd8c27495fbaa855603df4f774fe86bbc21743f59fd039f734feb07704805bd<\/td>\n<td>bt_install.sh<\/td>\n<td>Trojan.SH.DARKRADIATION.A<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>7a15e51e5dc6a9bfe0104f731e7def854abca5154317198dad73f32e1aead740<\/td>\n<td>binaryinject1.so<\/td>\n<td>Trojan.Linux.PROCHIDER.AA<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>c869261902a1364dd3decb2f8dce54b81621f20abd7204a427a3365c8dcc9d78<\/td>\n<td>exploit4.py<\/td>\n<td>Trojan.SH.EXPLOADER.AA<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>503276929ce5c56c626eaa5c3aca0e0160743bf3c8d415042dc3f9bb8c8b44a2<\/td>\n<td>exploit3.py<\/td>\n<td>Trojan.SH.EXPLOADER.AA<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>847d0057ade1d6ca0fedc5f48e76dd076fa4611deb77c490899f49701e87b6dd<\/td>\n<td>exploit1.py<\/td>\n<td>Trojan.SH.EXPLOADER.AA<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>14584a716c5378405cba188dd60cec03571965329f52cfbd8c54116fa2d59377<\/td>\n<td>pwd.c<\/td>\n<td>&nbsp;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span class=\"body-subhead-title\">C&amp;C Server IOCs<\/span><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Malware command and control server: 185[.]141[.]25[.]168<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Hack tools directory:&nbsp; hxxps[:\/\/]u2wgg22a111ssy[.]space<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Hack tools directory: hxxps[:\/\/]www[.]0zr33n33fo[.]space<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Hack tools directory: hxxp[:\/\/]vk-o2vox-n[.]pp[.]ua<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Hack tools directory: hxxps[:\/\/]m0troppm[.]site<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Hack tools directory: hxxps[:\/\/]apooow4[.]space<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Hack tools directory: hxxps[:\/\/]ga345ss34u[.]space<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/f\/bash-ransomware-darkradiation-targets-red-hat--and-debian-based-linux-distributions.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We investigate how certain hacking tools are used to move laterally on victims\u2019 networks to deploy ransomware. These tools contain reconnaissance\/spreader scripts, exploits for Red Hat and CentOS, binary injectors, and more. In this blog, we focus on analyzing the worm and ransomware script. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":42415,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9508,9539,9509],"class_list":["post-42414","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-endpoints","tag-trend-micro-research-ransomware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-17T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png\" \/>\n\t<meta property=\"og:image:width\" content=\"845\" \/>\n\t<meta property=\"og:image:height\" content=\"1042\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher\",\"datePublished\":\"2021-06-17T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/\"},\"wordCount\":2153,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Ransomware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/\",\"name\":\"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png\",\"datePublished\":\"2021-06-17T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png\",\"width\":845,\"height\":1042},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/","og_locale":"en_US","og_type":"article","og_title":"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-06-17T00:00:00+00:00","og_image":[{"width":845,"height":1042,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher","datePublished":"2021-06-17T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/"},"wordCount":2153,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Endpoints","Trend Micro Research : Ransomware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/","url":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/","name":"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png","datePublished":"2021-06-17T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/08\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher.png","width":845,"height":1042},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/bash-ransomware-darkradiation-targets-red-hat-and-debian-based-linux-distributions-threat-researcher\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Bash Ransomware DarkRadiation Targets Red Hat- and Debian-based Linux Distributions Threat Researcher"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=42414"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42414\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/42415"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=42414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=42414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=42414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}