New Linux-Based Ransomware Targets VMware Servers

'"Researchers at Trend Micro have discovered some new Linux-based ransomware that's being used to attack VMware ESXi servers," reports CSO Online. (They describe the ESXi servers as "a bare-metal hypervisor for creating and running several virtual machines that share the same hard drive storage.") Called Cheerscrypt, the bad app is following in the footsteps of other ransomware programs — such as LockBit, Hive and RansomEXX — that have found ESXi an efficient way to infect many computers at once with malicious payloads. Roger Grimes, a defense evangelist with security awareness training provider KnowBe4, explains that most of the world's organizations operate using VMware virtual machines. "It makes the job of ransomware attackers far easier because they can encrypt one server — the VMware server — and then encrypt every guest VM it contains. One compromise and encryption command can easily encrypt dozens to hundreds of other virtually run computers all at once." "Most VM shops use some sort of VM backup product to back up all guest servers, so finding and deleting or corrupting one backup repository kills the backup image for all the hosted guest servers all at once," Grimes adds.... The gang behind Cheerscrypt uses a "double extortion" technique to extract money from its targets, the researchers explain. "Security Alert!!!" the attackers' ransom message declares. "We hacked your company successfully. All files have been stolen and encrypted by us. If you want to restore your files or avoid file leaks, please contact us." -- source: https://linux.slashdot.org/story/22/05/28/2243237 Cheers, Peter -- Peter Reutemann Dept. of Computer Science University of Waikato, NZ +64 (7) 858-5174 (office) +64 (7) 577-5304 (home office) https://www.cs.waikato.ac.nz/~fracpete/ http://www.data-mining.co.nz/

On Mon, 30 May 2022 10:51:14 +1200, Peter Reutemann quoted:
'"Researchers at Trend Micro have discovered some new Linux-based ransomware that's being used to attack VMware ESXi servers," reports CSO Online."'
Speaking of which, Broadcom will be acquiring VMware for US$61 billion, and adopting the name “VMware” for the whole group <https://arstechnica.com/information-technology/2022/05/broadcom-will-pay-61-billion-to-become-the-latest-company-to-acquire-vmware/>. And for those who have paid one-off licence fees for VMware, those are going to be phased out in favour of a wholly subscription-based model <https://www.theregister.com/2022/05/27/broadcom_vmware_subscriptions/>.
participants (2)
-
Lawrence D'Oliveiro
-
Peter Reutemann