NamPoHyu aka MegaLocker Virus Ransomware Found Remotely Encrypting Samba Servers

April 18, 2019

A ransomware family was recently spotted targeting vulnerable Samba servers: NamPoHyu Virus aka MegaLocker Virus. NamPoHyu Virus searches for publicly accessible Samba servers, brute-forces them, and runs the ransomware locally to encrypt the exposed servers.

Ransomware: A type of malware that prevents or limits users from accessing their system, either by locking the system's screen or by locking the users' files unless a ransom is paid.