HomeSecurityAvosLocker ransomware: Linux version targets VMware ESXi servers

AvosLocker ransomware: Linux version targets VMware ESXi servers

AvosLocker is one of the latest ransomware and now it appears that the gang behind it has added support for encrypting Linux systems, specifically targeting VMware ESXi virtual machines.

AvosLocker ransomware Linux

According to BleepingComputer, there is at least one victim who was hit by this Linux variant of AvosLocker and received a ransom demand of 1 million dollars.

Several months ago, the AvosLocker gang was advertising its latest ransomware variants, Windows Avos2 and AvosLinux.

See also: New Night Sky ransomware targets corporate networks

“ The new variants (avos2 / avoslinux) have the best to offer: high performance and a high level of encryption compared to competitors ,” the gang said

Termination of ESXi virtual machines before encryption

When booted on a Linux system, AvosLocker ransomware will terminate all ESXi machines on the server, using the following command:

esxcli –formatter=csv –format-param=fields==”WorldID,DisplayName” vm process list | tail -n +2 | awk -F $’,’ ‘{system(“esxcli vm process kill –type=force –world-id=” $1)}’

Once it starts operating on a compromised system, the ransomware will append the .avoslinux to all encrypted files.

It will then display ransom notes. These notes ask victims to not shut down their computers if they want to avoid having their files destroyed, and suggest they visit an onion site to learn more details about how to pay the ransom.

See also: FinalSite: No school data stolen in ransomware attack

It is said that AvosLocker began targeting Linux systems in November 2021.

VMware ESXi

AvosLocker Ransomware: Turning to Linux

AvosLocker is a newer ransomware gang that first appeared in the summer of 2021 and called ransomware affiliates to join their new Ransomware-as-a-Service (RaaS) operation.

Targeting ESXi virtual machines aligns with the actions of their targets, who have started shifting to virtual machines for easier device management and more efficient resource usage.

By targeting VMs, ransomware operators also take advantage of the easier and faster encryption of multiple servers with a single command.

See also: More and more DDoS attacks demanding ransom

Recently, more and more ransomware gangs have been targeting Linux systems. Since October, the Hive ransomware has started encrypting Linux and FreeBSD systems using new variants of the malware. Earlier, security researchers had detected the REvil with a Linux encryptor targeting VMware ESXi VMs.

According to Emsisoft CTO Fabian Wosar, other ransomware gangs, including DarkSide, Babuk, RansomExx/Defray, Mespinoza, GoGoogle, and Hellokitty, have also created and used their own Linux encryptors.

“The reason why most ransomware groups implemented a Linux-based version of their ransomware is to specifically target ESXi,” Wosar explained.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS