Skip to main content

Threats Tagged 'esxi'

View all threats tagged with 'esxi'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: esxi

Threats Tagged 'esxi'

Click on any threat for detailed analysis and mitigation recommendations

GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

Join the discussion

Check Point Research discovered critical flaws in VECT 2.0 ransomware affecting Windows, Linux, and ESXi platforms. A fundamental encryption implementation error causes files larger than 128 KB to be permanently destroyed rather than encrypted. The malware uses ChaCha20-IETF cipher but only saves one of four decryption nonces required for large files, making recovery impossible even after ransom payment. VECT's encryption speed modes are non-functional, thread scheduling degrades performance, and anti-analysis code is unreachable. Despite partnerships with TeamPCP and BreachForums for distribution, the technical implementation demonstrates amateur execution behind a professional facade. The nonce-handling flaw exists across all platform variants since initial deployment, effectively transforming this ransomware into a wiper for enterprise assets including VM disks, databases, and backups.

Join the discussion

Kyber ransomware represents a significant threat through dual-platform deployment capabilities targeting VMware ESXi virtualization infrastructure and Windows file systems. During a March 2026 incident response engagement, two Kyber payloads were recovered from the same environment. The ESXi variant, written in C++, specifically targets VMware environments with datastore encryption, VM termination, and management interface defacement capabilities. The Windows variant, written in Rust, includes experimental Hyper-V targeting features. Both samples share campaign identifiers and Tor-based infrastructure, confirming coordinated cross-platform operations. Despite advertising post-quantum Kyber1024 encryption, the ESXi variant actually uses ChaCha8 with RSA-4096 key wrapping, while the Windows variant implements the claimed AES-256-CTR with Kyber1024 hybrid scheme. The ransomware includes anti-recovery measures, service termination, and effective encryption strategies designed to cause complete operational disr...

Join the discussion

LockBit 5.0, the latest version of the notorious ransomware, has been released with support for Windows, Linux, and ESXi systems. This update brings improved defense evasion, faster encryption, and enhanced modularity. The Windows variant employs extensive anti-analysis techniques, while Linux and ESXi versions remain unpacked. All variants share a common encryption scheme using XChaCha20 and Curve25519. LockBit 5.0 demonstrates a focus on enterprise and infrastructure targets, including explicit support for Proxmox virtualization. The group's data leak site reveals a primary focus on the U.S.business sector, with victims spanning various industries. LockBit's infrastructure has shown connections to SmokeLoader, suggesting possible cooperation or infrastructure reuse among malware operators.

Join the discussion

RansomHouse, a ransomware-as-a-service operated by the Jolly Scorpius group, has upgraded its encryption capabilities with a new version of its Mario ransomware component. This upgrade introduces a sophisticated two-stage encryption process, enhanced memory management, and dynamic file processing, making the ransomware more efficient and harder to analyze. The attack chain involves MrAgent managing deployments and Mario performing file encryption, primarily targeting virtualized environments such as ESXi servers. Although no known exploits are currently in the wild, the improvements signal a trend toward more resilient ransomware variants. European organizations using virtualized infrastructure are at risk, especially those with ESXi deployments. The threat requires no known CVE but poses a medium severity risk due to its complexity and potential impact on availability and data confidentiality. Mitigation should focus on securing virtualization platforms, monitoring for indicators of compromise, and implementing robust backup and recovery strategies. Countries with high virtualization adoption and critical infrastructure reliance on virtual environments are most likely to be affected.

Join the discussion

'The Gentlemen' ransomware group, active since July 2025, operates a Ransomware-as-a-Service (RaaS) platform that employs advanced dual-extortion tactics by encrypting data and exfiltrating sensitive information to coerce ransom payments. Their ransomware targets Windows, Linux, and ESXi platforms, encrypting both local and network-shared drives using strong cryptographic algorithms XChaCha20 and Curve25519. Recent updates include automatic self-restart, run-on-boot persistence, configurable encryption speeds, and attack methods, enhancing their operational resilience and adaptability. The group has publicly disclosed 47 victims within two months, indicating rapid propagation and impact. The malware leverages multiple MITRE ATT&CK techniques such as persistence (T1547.001), data encryption (T1486), and network share discovery (T1135). No known exploits or CVEs are associated yet, but the threat is significant due to its multi-platform support and dual-extortion approach. European organizations with mixed OS environments and ESXi virtualization are at particular risk. Mitigation requires tailored detection of persistence mechanisms, network segmentation, and robust incident response plans. Countries with high adoption of VMware ESXi and diverse enterprise IT infrastructures, such as Germany, France, and the UK, are likely most affected.

Join the discussion

Trend Research analyzed the latest version of LockBit ransomware, LockBit 5.0, which exhibits advanced obfuscation, anti-analysis techniques, and cross-platform capabilities for Windows, Linux, and ESXi systems. The Windows variant uses heavy obfuscation and packing, loading its payload through DLL reflection and implementing anti-analysis techniques. The Linux variant has similar functionality with command-line options for targeting specific directories and file types. The ESXi variant specifically targets VMware virtualization infrastructure. All variants use randomized 16-character file extensions, have Russian language system avoidance, and clear event logs post-encryption. The existence of multiple variants confirms LockBit's continued cross-platform strategy, enabling simultaneous attacks across entire enterprise networks including virtualized environments.

Join the discussion

A newly emerged ransomware group called BERT has been targeting organizations across Asia and Europe since April. The group employs simple code with effective execution, impacting sectors such as healthcare, technology, and event services. BERT's ransomware operates on both Windows and Linux platforms, using PowerShell-based loaders, privilege escalation, and concurrent file encryption. On Linux systems, it can support up to 50 threads for fast encryption and forcibly shut down ESXi virtual machines. The group's tactics include disabling security features, terminating specific processes, and using standard encryption algorithms. BERT's variants have evolved, streamlining their encryption process and expanding their targeting activities. The Linux variant shows similarities to the REvil ransomware, suggesting possible code reuse.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: esxi
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses