Linux version of TargetCompany ransomware focuses on VMware ESXi
ID: 1d525112-45cc-57eb-a59c-a1275858b58c
STIX ID: report--1d525112-45cc-57eb-a59c-a1275858b58c
Feed Name: Bleeping Computer
Trend Micro reports a Linux variant of the TargetCompany ransomware family (aka Mallox/FARGO/Tohnichi) that targets VMware ESXi hosts: a custom shell script verifies administrative privileges and ESXi via uname, exfiltrates a "TargetInfo.txt" to C2 servers, encrypts VM-related file extensions appending ".locked", drops a ransom note, and removes the payload to hinder forensics; activity is attributed to an affiliate called "vampire" and the report includes IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
