Operational Blackout: How Kyber Ransomware Targets the Heart of Virtualized Environments
ID: d2c71add-6b3c-553d-87cd-ddf515f32fde
STIX ID: report--d2c71add-6b3c-553d-87cd-ddf515f32fde
Feed Name: securityonline.info
Rapid7 analyzed 'Kyber', a specialized dual-platform ransomware family designed to target VMware ESXi virtualization and Windows file servers. The ESXi variant is a 64-bit C++ ELF that enumerates and cleanly shuts down VMs, defaces the VMware web UI, and persists as a background process while using ChaCha8 with RSA-4096; the Windows Rust variant targets Hyper-V and includes aggressive anti-recovery measures (VSS wiping, disabling WinRE), process termination via Restart Manager, and file icon manipulation. Operators claim Kyber1024 usage, but Rapid7 found discrepancies between the ransom notes and actual cryptography; the cross-platform focus and destructive anti-recovery toolkit raise the risk of a complete operational blackout for affected organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
