Linux Variant of Helldown Ransomware Targets VMware ESXi Systems
ID: 931d8a25-9a3f-5fde-9013-7ccd24d0c1b0
STIX ID: report--931d8a25-9a3f-5fde-9013-7ccd24d0c1b0
Feed Name: Dark Reading
Helldown, a rapidly emerging ransomware family, has introduced a Linux variant that targets VMware ESXi environments and has been linked to at least 31 victims across multiple sectors. Evidence suggests the actors exploited undocumented or recently patched Zyxel firewall vulnerabilities to gain initial access (notably creating an account named OKSDW82A and uploading zzz1.conf), then used SSL VPN tunnels to pivot, relied on living-off-the-land tools (PowerShell, certutil, PSExec), remote access tools (TeamViewer, RDP), credential theft (Mimikatz), and anti-forensics (HRSword and disk overwrites) while exfiltrating unusually large volumes of data for extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
