logo

Kraken Ransomware Expands Attacks to Windows, Linux, and VMware ESXi Systems

ID: 9180593e-3bb1-53c2-92b1-65d56f4484da

STIX ID: report--9180593e-3bb1-53c2-92b1-65d56f4484da

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2025-11-14

Date Updated: 2026-04-19

Author: Priya

...
...

Cisco Talos describes Kraken, a Russian-speaking ransomware group that evolved from HelloKitty and is conducting big‑game‑hunting, double‑extortion attacks using distinct Windows, Linux, and ESXi encryptors. Observed TTPs include SMB exploitation for initial access, administrator credential harvesting, RDP reuse, use of Cloudflared and SSHFS for persistence and exfiltration, strong cryptography (RSA‑4096 and ChaCha20), encryption benchmarking, VM termination on ESXi, deletion of backups/logs, and indicators such as the .zpsc file extension, readme_you_ws_hacked.txt ransom note, Snort SIDs, and ClamAV signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.