logo

AvosLocker Ransomware Targets VMware ESXi Servers

ID: ae46ae56-1768-51a3-9e06-a138b15a3e7b

STIX ID: report--ae46ae56-1768-51a3-9e06-a138b15a3e7b

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

Cyble Research Labs reports a Linux variant of AvosLocker ransomware targeting VMware ESXi/VMFS hosts: actors exploit ProxyShell Exchange vulnerabilities to gain access, use Mimikatz to harvest credentials and obtain RDP/domain access, then deploy a multithreaded ELF ransomware that kills VMs, appends the .avoslinux extension, drops README_FOR_RESTORE.txt ransom notes, and extorts victims via a TOR payment site; the report provides static analysis, IOCs (SHA256 hashes and .onion URLs), observed ransom amounts, leak-site activity and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.