AvosLocker is one of the latest ransomware and now it appears that the gang behind it has added support for encrypting Linux systems, specifically targeting VMware ESXi virtual machines.

According to BleepingComputer, there is at least one victim who was hit by this Linux variant of AvosLocker and received a ransom demand of 1 million dollars.
Several months ago, the AvosLocker gang was advertising its latest ransomware variants, Windows Avos2 and AvosLinux.
See also: New Night Sky ransomware targets corporate networks
“ The new variants (avos2 / avoslinux) have the best to offer: high performance and a high level of encryption compared to competitors ,” the gang said
Termination of ESXi virtual machines before encryption
When booted on a Linux system, AvosLocker ransomware will terminate all ESXi machines on the server, using the following command:
esxcli –formatter=csv –format-param=fields==”WorldID,DisplayName” vm process list | tail -n +2 | awk -F $’,’ ‘{system(“esxcli vm process kill –type=force –world-id=” $1)}’
Once it starts operating on a compromised system, the ransomware will append the .avoslinux to all encrypted files.
It will then display ransom notes. These notes ask victims to not shut down their computers if they want to avoid having their files destroyed, and suggest they visit an onion site to learn more details about how to pay the ransom.
See also: FinalSite: No school data stolen in ransomware attack
It is said that AvosLocker began targeting Linux systems in November 2021.

AvosLocker Ransomware: Turning to Linux
AvosLocker is a newer ransomware gang that first appeared in the summer of 2021 and called ransomware affiliates to join their new Ransomware-as-a-Service (RaaS) operation.
Targeting ESXi virtual machines aligns with the actions of their targets, who have started shifting to virtual machines for easier device management and more efficient resource usage.
By targeting VMs, ransomware operators also take advantage of the easier and faster encryption of multiple servers with a single command.
See also: More and more DDoS attacks demanding ransom
Recently, more and more ransomware gangs have been targeting Linux systems. Since October, the Hive ransomware has started encrypting Linux and FreeBSD systems using new variants of the malware. Earlier, security researchers had detected the REvil with a Linux encryptor targeting VMware ESXi VMs.
According to Emsisoft CTO Fabian Wosar, other ransomware gangs, including DarkSide, Babuk, RansomExx/Defray, Mespinoza, GoGoogle, and Hellokitty, have also created and used their own Linux encryptors.
“The reason why most ransomware groups implemented a Linux-based version of their ransomware is to specifically target ESXi,” Wosar explained.
Source: Bleeping Computer
