{"id":3999,"date":"2022-01-24T20:19:40","date_gmt":"2022-01-25T01:19:40","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3999"},"modified":"2022-01-24T20:19:41","modified_gmt":"2022-01-25T01:19:41","slug":"tellyouthepass-returns-and-attacks-windows-and-linux","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/","title":{"rendered":"TellYouThePass returns and attacks Windows and Linux"},"content":{"rendered":"\n<p>Threat actors have revived an old and relatively dormant ransomware family known as TellYouThePass, deploying it in attacks against Windows and Linux devices targeting a critical remote code execution bug in the Apache Log4j library.<\/p>\n\n\n\n<p>The common form of invasion used by the group is through email attachments, usually as Microsoft Word files. Once the file is downloaded, the ransomware is installed and preparations for encryption begin. All programs that could prevent encryption are disabled, and then encryption starts. Then, after making the files inaccessible through encryption, the &#8216;.locked&#8217; extension is added to the files. TellYouThePass targets large files such as: media, images, databases, PDFs, Word documents, and others.<\/p>\n\n\n\n<p>It should be noted that this is not the first time that the Tellyouthepass ransomware has used high-risk vulnerabilities to launch attacks, since last year, it had used the Eternal Blue vulnerabilities to attack multiple organizational units.<\/p>\n\n\n\n<p>TellYouThePass is not the first ransomware strain deployed in Log4Shell attacks since financially motivated attackers began injecting Monero miners into compromised systems and state-backed hackers began exploiting it to create footholds for tracking activity.<\/p>\n\n\n\n<p>Remember that if you were attacked by n ransomware there is no guarantee that your data will be returned to you after paying, so it is important to have backups. All government authorities strongly advise against paying ransoms as this only provides these criminals with more funding to continue their crimes.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors have revived an old and relatively dormant ransomware family known as TellYouThePass, deploying it in attacks against Windows and Linux devices targeting a critical remote code execution bug in the Apache Log4j library. The common form of invasion used by the group is through email attachments, usually as Microsoft Word files. Once the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4001,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3999","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TellYouThePass returns and attacks Windows and Linux - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today we will talk about a ransomware called TellYouThePass that was inactive for a long time and was revived by criminals.........\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TellYouThePass returns and attacks Windows and Linux - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today we will talk about a ransomware called TellYouThePass that was inactive for a long time and was revived by criminals.........\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-01-25T01:19:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-01-25T01:19:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/01\/Ransom.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1100\" \/>\n\t<meta property=\"og:image:height\" content=\"733\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"TellYouThePass returns and attacks Windows and Linux\",\"datePublished\":\"2022-01-25T01:19:40+00:00\",\"dateModified\":\"2022-01-25T01:19:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/\"},\"wordCount\":240,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/Ransom.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/\",\"name\":\"TellYouThePass returns and attacks Windows and Linux - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/Ransom.jpg\",\"datePublished\":\"2022-01-25T01:19:40+00:00\",\"dateModified\":\"2022-01-25T01:19:41+00:00\",\"description\":\"Today we will talk about a ransomware called TellYouThePass that was inactive for a long time and was revived by criminals.........\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/Ransom.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/Ransom.jpg\",\"width\":1100,\"height\":733},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tellyouthepass-returns-and-attacks-windows-and-linux\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TellYouThePass returns and attacks Windows and Linux\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TellYouThePass returns and attacks Windows and Linux - Truxgo Server Blog","description":"Today we will talk about a ransomware called TellYouThePass that was inactive for a long time and was revived by criminals.........","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/","og_locale":"es_MX","og_type":"article","og_title":"TellYouThePass returns and attacks Windows and Linux - Truxgo Server Blog","og_description":"Today we will talk about a ransomware called TellYouThePass that was inactive for a long time and was revived by criminals.........","og_url":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-01-25T01:19:40+00:00","article_modified_time":"2022-01-25T01:19:41+00:00","og_image":[{"width":1100,"height":733,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/01\/Ransom.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"TellYouThePass returns and attacks Windows and Linux","datePublished":"2022-01-25T01:19:40+00:00","dateModified":"2022-01-25T01:19:41+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/"},"wordCount":240,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/01\/Ransom.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/","url":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/","name":"TellYouThePass returns and attacks Windows and Linux - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/01\/Ransom.jpg","datePublished":"2022-01-25T01:19:40+00:00","dateModified":"2022-01-25T01:19:41+00:00","description":"Today we will talk about a ransomware called TellYouThePass that was inactive for a long time and was revived by criminals.........","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/01\/Ransom.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/01\/Ransom.jpg","width":1100,"height":733},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/tellyouthepass-returns-and-attacks-windows-and-linux\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"TellYouThePass returns and attacks Windows and Linux"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3999","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3999"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3999\/revisions"}],"predecessor-version":[{"id":4002,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3999\/revisions\/4002"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4001"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3999"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3999"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}