logo

New VanHelsing ransomware targets Windows, ARM, ESXi systems

ID: 172d62ee-f83f-5995-811c-a1e7f90c3da7

STIX ID: report--172d62ee-f83f-5995-811c-a1e7f90c3da7

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-03-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

VanHelsing is a newly promoted multi-platform ransomware-as-a-service operation that targets Windows, Linux, BSD, ARM and ESXi systems. Reported in March, the RaaS offers affiliates automated operational tooling, stores stolen data on operator servers, and lists active victims (including a U.S. city and companies) with a reported $500,000 demand; the malware uses per-file ChaCha20 encryption with Curve25519-wrapped keys and includes a stealth mode that decouples encryption from renaming to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.