New VanHelsing ransomware targets Windows, ARM, ESXi systems
ID: 172d62ee-f83f-5995-811c-a1e7f90c3da7
STIX ID: report--172d62ee-f83f-5995-811c-a1e7f90c3da7
Feed Name: Bleeping Computer
VanHelsing is a newly promoted multi-platform ransomware-as-a-service operation that targets Windows, Linux, BSD, ARM and ESXi systems. Reported in March, the RaaS offers affiliates automated operational tooling, stores stolen data on operator servers, and lists active victims (including a U.S. city and companies) with a reported $500,000 demand; the malware uses per-file ChaCha20 encryption with Curve25519-wrapped keys and includes a stealth mode that decouples encryption from renaming to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
