logo

Linux version of RansomHub ransomware targets VMware ESXi VMs

ID: 940080c0-5a77-5b19-9fd1-d3e131353671

STIX ID: report--940080c0-5a77-5b19-9fd1-d3e131353671

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-06-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

RansomHub, a Ransomware-as-a-Service operation active since February 2024 and linked to other ransomware families, is deploying a C++ VMware ESXi encryptor targeting virtualized enterprise environments; it supports ESXi-specific commands (snapshot deletion, VM shutdown), disables logging, partially encrypts VM files using ChaCha20 with Curve25519, and writes ransom notes to login/web interfaces. Recorded Future reports confirm a multi-OS capability (Windows, Linux, ESXi) with 45+ claimed victims in 18 countries, and researchers identified a flaw where placing '-1' in /tmp/app.pid causes the ESXi binary to enter an infinite loop, providing a temporary mitigation opportunity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.