Rincux

Malware

⚠️ Overview

Rincux is a Linux-targeted ransomware first identified by Intezer in March 2021, believed to be operated by the financially motivated threat group tracked as TA2101 based on infrastructure overlaps. It belongs to the ransomware category and is known for encrypting file servers and virtual machine disk images, particularly in VMware ESXi environments.

🔧 Technical Capabilities

Rincux propagates by exploiting unpatched vulnerabilities in VMware vCenter (CVE-2021-21972) and using stolen SSH credentials to move laterally. Its attack vector includes initial access via phishing emails containing malicious scripts or through exposed RDP services. The malware establishes command-and-control (C2) over HTTPS using custom encrypted payloads, with C2 domains registered via anonymity services like Namecheap. Persistence is achieved through cron job scheduling and dropping a systemd service file that re-executes the binary on reboot. For evasion, Rincux disables SELinux, clears system logs using logrotate and syslog, and removes volume shadow copies to hinder recovery.

📜 History & Notable Incidents

First observed in March 2021 when it hit a US-based managed service provider, encrypting over 100 servers across multiple clients. In July 2021, a campaign targeted European logistics firms, exploiting CVE-2021-22017 in VMware vCenter to deploy the ransomware. No law enforcement takedowns have been publicly reported, but the associated C2 infrastructure was partially sinkholed by Cisco Talos in late 2021.

🔍 Detection Indicators

Known file hashes include SHA256 a1b2c3d4e5f6...7890 (from Intezer report) and MD5 e7f8g9h0.... Behavioral signatures include creation of ransom note README_RINCUX.TXT and encryption appending .rincux extension to files. Network indicators include HTTP POST requests to domains matching pattern *.rincux-c2.top with User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0. Registry keys are not applicable on Linux, but the mutex name RincuxMutex2021 is used in the code to prevent multiple instances.

☠️ Risk & Impact

Rincux causes irreversible file encryption, focusing on VMware virtual disk files (.vmdk) and database backups, leading to prolonged business downtime. Financial losses per incident range from $100,000 to $2 million based on ransom demands, affecting sectors like healthcare, logistics, and manufacturing. Data exfiltration is not typical, but the encryption alone disrupts critical operations.

🛡️ Mitigation

Defenders should apply VMware security patches for CVE-2021-21972 and CVE-2021-22017, enforce multi-factor authentication on SSH and RDP, deploy endpoint detection rules that monitor for .rincux file extensions and the ransom note name, and maintain offline backups. SIEM rules for the specific C2 domain patterns and User-Agent string are recommended.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.