HomeSecurityHive ransomware: Changes Linux VMware ESXi cryptographer to Rust

Hive ransomware: Changes Linux VMware ESXi encryptor to Rust

Hive ransomware has converted the VMware ESXi Linux to the Rust programming language and added new features to make it harder for security researchers to monitor ransom negotiations.

See also: Rompetrol gas station network hit by Hive ransomware

hive ransomware

As businesses increasingly rely on virtual machines for resource savings, server consolidation, and easier backups, ransomware gangs are creating dedicated encryptors that focus on these services.

Linux cryptojackers typically target VMware ESXI virtualization platforms as they are the most commonly used in enterprises.

While the Hive enterprise has been using a Linux cryptographer to target VMware ESXi servers for some time, a recent sample demonstrated that it updated its cryptographer with features first introduced by the BlackCat/ALPHV ransomware operation.

When ransomware companies attack a victim, they try to conduct their negotiations privately, telling victims that if the ransom is not paid, their data will be published and their reputation will suffer.

However, when ransomware samples are uploaded to public malware analysis services, they are usually detected by security researchers who can extract the ransom note and monitor the negotiations.

See also: BEC scams cost victims more than ransomware

In many cases, these negotiations are then published on Twitter and elsewhere, resulting in the negotiations failing.

rust

The BlackCat removed the URLs of Tor negotiations from its encryption to prevent this from happening. This feature prevents researchers who find the sample from retrieving the URL, as it is not included in the executable file and is only passed to the executable at runtime.

In a new Hive Linux cryptojacking vulnerability found by Group-IB security researcher rivitna , the Hive feature now requires the attacker to provide the login username and password as a command-line argument when launching the malware.

Copying BlackCat's tactics, the Hive ransomware gang made it impossible to recover negotiated login credentials from Linux malware samples, with the credentials now only available in ransom notes created during the attack.

"Rust allows for safer, faster, and more efficient code, while code optimization complicates Rust program analysis," Rivitna said.

See also: Which ransomware encrypts data the fastest? (comparison of 10 variants)

As encryption of VMware ESXi virtual machines is a critical part of a successful attack, ransomware operations are constantly evolving their code not only to be more effective, but also to keep operations and negotiations secret.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS