The company behind REvil ransomware is now using a Linux cryptographer that targets and encrypts Vmware ESXi virtual machines.

See also: Grupo Fleury attacked by REVIL ransomware
As business moves to virtual machines for easier backups, device management, and efficient resource utilization, ransomware gangs are increasingly creating their own tools to mass encrypt the storage used by VMs.
In May, Advanced Intel's Yelisey Boguslavskiy shared a forum post from REvil Operation, where they confirmed that they had released a Linux version of their encryptor that could also work on NAS devices.
See also: REVIL ransomware hits nuclear weapons company Sol Oriens
Today, security researcher MalwareHunterTeam detected a Linux variant of REvil ransomware (also known as Sodinokibi) that also appears to target ESXi servers.
Intel's Vitali Kremez, who analyzed the new REvil Linux variant, told BleepingComputer that it is an ELF64 executable and includes the same configuration options used by most common Windows executables.
Kremez states that this is the first known time the Linux variant has been publicly available since its release.
When executed on a server, a threat actor can determine the encryption path and activate a silent operation, as shown in the usage instructions below.

When run on ESXi servers, it will run the esxcli command line tool to list all running ESXi virtual machines and terminate them.

See also: JBS: Paid $11 million ransom to REvil ransomware group
This command is used to close the virtual machine disk (VMDK) files stored in the /vmfs/ folder so that the REvil malware can encrypt the files without being locked by ESXi.
If a virtual machine is not properly shut down before encrypting its file, it could lead to data corruption, as explained by Emsisoft CTO Fabian Wosar.
By targeting virtual machines in this way, REvil can encrypt multiple servers at once with a single command.
Information source: bleepingcomputer.com
