Feature-rich Ensiko malware can encrypt, targets Windows, macOS, Linux

CyberPanther

Level 7
Thread author
Verified
Well-known
Oct 1, 2019
298
1,902
569
Saudi Arabia
Threat researchers have found a new feature-rich malware that can encrypt files on any system running PHP, making it a high risk for Windows, macOS, and Linux web servers.

The malware received the name Ensiko and is a web shell written in PHP. Attackers can use it to remotely control a compromised system and run a host of malicious activities.
 
"Conclusion

Ensiko is a web shell used by an attacker that enables remote administration, file encryption, and many more features on a compromised web server. A common method to deploy web shell is exploiting web application vulnerabilities or *gaining access to an already compromised server."

It sounds like this malware targets web servers, not ordinary PCs.