New Play ransomware Linux version targets VMware ESXi VMs
ID: 1ae0bdab-5e16-5c9c-a218-f346222a06db
STIX ID: report--1ae0bdab-5e16-5c9c-a218-f346222a06db
Feed Name: Bleeping Computer
Trend Micro has observed Play ransomware deploying a dedicated Linux locker that detects VMware ESXi hosts, powers off virtual machines (using vim-cmd), and encrypts VMFS files appending the .PLAY extension; the group also performs double-extortion and drops ransom notes visible in ESXi consoles. The variant targets ESXi environments to maximize disruption to enterprise operations; the FBI, CISA and ACSC warned the gang had breached roughly 300 organizations through October 2023 and recommended MFA, offline backups, and up-to-date software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
