logo

New Play ransomware Linux version targets VMware ESXi VMs

ID: 1ae0bdab-5e16-5c9c-a218-f346222a06db

STIX ID: report--1ae0bdab-5e16-5c9c-a218-f346222a06db

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-07-22

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Trend Micro has observed Play ransomware deploying a dedicated Linux locker that detects VMware ESXi hosts, powers off virtual machines (using vim-cmd), and encrypts VMFS files appending the .PLAY extension; the group also performs double-extortion and drops ransom notes visible in ESXi consoles. The variant targets ESXi environments to maximize disruption to enterprise operations; the FBI, CISA and ACSC warned the gang had breached roughly 300 organizations through October 2023 and recommended MFA, offline backups, and up-to-date software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.