logo

Ransomware gang uses ISPsystem VMs for stealthy payload delivery

ID: fe326906-5bb1-522f-9216-05db89d65661

STIX ID: report--fe326906-5bb1-522f-9216-05db89d65661

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Sophos researchers found that threat actors (including LockBit, Qilin, Conti, BlackCat/ALPHV, Ursnif, and operators of RedLine and Lummar) are exploiting ISPsystem VMmanager's default Windows VM templates—which reuse identical hostnames and system identifiers—to spin up VMs for C2 and delivery of ransomware and info-stealer payloads; the technique hides malicious systems among legitimate infrastructure and is concentrated in a small set of hosting providers that enable large-scale abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.