AvosLocker Ransomware Targets VMware ESXi Servers
ID: ae46ae56-1768-51a3-9e06-a138b15a3e7b
STIX ID: report--ae46ae56-1768-51a3-9e06-a138b15a3e7b
Feed Name: Cyble Blog
Cyble Research Labs reports a Linux variant of AvosLocker ransomware targeting VMware ESXi/VMFS hosts: actors exploit ProxyShell Exchange vulnerabilities to gain access, use Mimikatz to harvest credentials and obtain RDP/domain access, then deploy a multithreaded ELF ransomware that kills VMs, appends the .avoslinux extension, drops README_FOR_RESTORE.txt ransom notes, and extorts victims via a TOR payment site; the report provides static analysis, IOCs (SHA256 hashes and .onion URLs), observed ransom amounts, leak-site activity and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
