logo

Linux version of TargetCompany ransomware focuses on VMware ESXi

ID: 1d525112-45cc-57eb-a59c-a1275858b58c

STIX ID: report--1d525112-45cc-57eb-a59c-a1275858b58c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-06-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Trend Micro reports a Linux variant of the TargetCompany ransomware family (aka Mallox/FARGO/Tohnichi) that targets VMware ESXi hosts: a custom shell script verifies administrative privileges and ESXi via uname, exfiltrates a "TargetInfo.txt" to C2 servers, encrypts VM-related file extensions appending ".locked", drops a ransom note, and removes the payload to hinder forensics; activity is attributed to an affiliate called "vampire" and the report includes IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.