Gentlemen RaaS Adds C-Based ESXi Locker To Cross-Platform Attacks
ID: 6c496eb3-7ed5-56e7-b217-9c534dfd5470
STIX ID: report--6c496eb3-7ed5-56e7-b217-9c534dfd5470
Feed Name: Cyber Press
The report describes The Gentlemen RaaS escalating enterprise attacks by deploying a specialized C-based ESXi locker that forcefully powers off VMs, manipulates VMFS storage behavior, and encrypts virtual disks using a hybrid XChaCha20/X25519 scheme with configurable intermittent encryption speeds; affiliates are also using SystemBC to operate a global proxy botnet of over 1,570 infected hosts and employing automated lateral movement techniques while disabling backups and recovery services to maximize impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
