logo

Operational Blackout: How Kyber Ransomware Targets the Heart of Virtualized Environments

ID: d2c71add-6b3c-553d-87cd-ddf515f32fde

STIX ID: report--d2c71add-6b3c-553d-87cd-ddf515f32fde

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Ddos

...
...

Rapid7 analyzed 'Kyber', a specialized dual-platform ransomware family designed to target VMware ESXi virtualization and Windows file servers. The ESXi variant is a 64-bit C++ ELF that enumerates and cleanly shuts down VMs, defaces the VMware web UI, and persists as a background process while using ChaCha8 with RSA-4096; the Windows Rust variant targets Hyper-V and includes aggressive anti-recovery measures (VSS wiping, disabling WinRE), process termination via Restart Manager, and file icon manipulation. Operators claim Kyber1024 usage, but Rapid7 found discrepancies between the ransom notes and actual cryptography; the cross-platform focus and destructive anti-recovery toolkit raise the risk of a complete operational blackout for affected organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.