(NOTE: I’ve restored my site thanks to Linux and some Updraft backups, but I am keeping this here for posterity)
It’s likely that not many people care about this, but I am writing this on my localhost/ blog — which I normally use as a backup to my blog at mathewingram.com/work — because the machine hosting that blog (and my photo server and my Plex instance and a bunch of other things) got hacked by ransomware a few days ago. I am currently in the process of either trying to restore it or wiping it and starting again, and at this point I have to say that the latter seems more likely.
I got hacked by someone using a form of ransomware known as Lockbit, which gets root access and encrypts all of your files and then renames them with a .lockbit extension. In my case it also got access to my Google Drive — I assume by cloning an authentication token to get around two-factor — and uploaded a bunch of encrypted files and backups. It seems that either I interrupted the process or they weren’t very good, because they didn’t get all of the files and they didn’t upload that many before I changed my passwords and locked them out.
That said, however, they screwed things up badly enough that it’s going to take some time and effort to put them back together, and it may not be possible. Ironically it would be easier if they had finished the job, because the last phase is to upload a ransom note and leave it as a screen saver, and that note often contains a unique ID that can be entered into an Interpol database that has decryption keys for some kinds of ransomware. If I can’t find a note or unique ID then I can’t search for the decryption key.
My working theory is that the hackers got in by brute-forcing the Windows Remote Desktop protocol, which I used to access my machine, since it is located somewhere other than my house. I had recently switched from RealVNC to RDP because RealVNC was charging a lot of money (relatively speaking) and RDP is free. I tried to set up Zerotier, a VPN, to get in through but it didn’t work for some reason I’ve been unable to figure out, so I opened a port to redirect RDP through — not the usual RDP port but a different one. A little while later there were a lot of blocked login attempts, but I didn’t think anything of it because open ports are often scanned and I thought I was protected enough, but clearly that wasn’t the case!
Anyway, even if I wipe the machine nothing priceless or irretrievable will be lost, because after many disk failures and other similar incidents in the past I have learned to have multiple redundant backups of almost everything, so I am all good on that front. But it will take some time to put things back where they belong — and maybe I will either go with Linux this time, or spend a bit more time trying to get a VPN working properly!

One Reply to “If you’re looking for mathewingram.com I have some bad news”