Linux version of RansomHub ransomware targets VMware ESXi VMs
ID: 940080c0-5a77-5b19-9fd1-d3e131353671
STIX ID: report--940080c0-5a77-5b19-9fd1-d3e131353671
Feed Name: Bleeping Computer
RansomHub, a Ransomware-as-a-Service operation active since February 2024 and linked to other ransomware families, is deploying a C++ VMware ESXi encryptor targeting virtualized enterprise environments; it supports ESXi-specific commands (snapshot deletion, VM shutdown), disables logging, partially encrypts VM files using ChaCha20 with Curve25519, and writes ransom notes to login/web interfaces. Recorded Future reports confirm a multi-OS capability (Windows, Linux, ESXi) with 45+ claimed victims in 18 countries, and researchers identified a flaw where placing '-1' in /tmp/app.pid causes the ESXi binary to enter an infinite loop, providing a temporary mitigation opportunity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
