logo

Researchers spot 700 percent increase in hypervisor ransomware attacks

ID: c7701fb9-ceaa-52a9-ba3a-7ddae176b24a

STIX ID: report--c7701fb9-ceaa-52a9-ba3a-7ddae176b24a

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Huntress reports a sharp increase in hypervisor-targeting ransomware—rising from 3% to 25% of malicious encryption activity in the latter half of the year—driven primarily by the Akira group; adversaries are exploiting weak hypervisor defenses to bypass endpoint protections, deploy encryption directly through hypervisors (including using built-in tools like OpenSSL), and misuse management utilities, prompting recommendations to enforce MFA, apply patches, use allow-listing, and monitor hypervisor logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.