Kraken Ransomware Expands Attacks to Windows, Linux, and VMware ESXi Systems
ID: 9180593e-3bb1-53c2-92b1-65d56f4484da
STIX ID: report--9180593e-3bb1-53c2-92b1-65d56f4484da
Feed Name: Cyber Press
Cisco Talos describes Kraken, a Russian-speaking ransomware group that evolved from HelloKitty and is conducting big‑game‑hunting, double‑extortion attacks using distinct Windows, Linux, and ESXi encryptors. Observed TTPs include SMB exploitation for initial access, administrator credential harvesting, RDP reuse, use of Cloudflared and SSHFS for persistence and exfiltration, strong cryptography (RSA‑4096 and ChaCha20), encryption benchmarking, VM termination on ESXi, deletion of backups/logs, and indicators such as the .zpsc file extension, readme_you_ws_hacked.txt ransom note, Snort SIDs, and ClamAV signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
