Black Basta ransomware now has the ability to encrypt VMware ESXi (VMs) running on corporate Linux servers.
See also: QBot malware and Black Basta ransomware collaborate and target companies

Most ransomware groups are now focusing attacks on ESXi virtual machines as they target more and more companies. It also makes it possible to leverage the faster encryption of multiple servers with a single command.
Virtual machine encryption is the new choice of cybercriminals, as many companies have recently migrated to virtual machines, which allow them to manage devices more easily and use their resources much more efficiently.
In a new report, analysts at Uptycs Threat Research revealed that they have detected new Black Basta ransomware binaries, specifically targeting VMWare ESXi servers.
Linux ransomware encryptors are nothing new, as similar encryptors have been released by many other gangs, including LockBit, HelloKitty, BlackMatter, REvil, AvosLocker, RansomEXX, and Hive.
See also: Black Basta ransomware: Dozens of attacks in just a few weeks
Like other Linux encryptors, the Black Basta ransomware binary will search for the /vmfs/volumes where virtual machines are stored on compromised ESXi servers.

The ransomware uses the ChaCha20 to encrypt files. It also exploits multithreading to utilize multiple processors and speed up the encryption process.
During encryption, the ransomware will add the .basta to the names of encrypted files and create ransom notes named readme.txt in each folder.
The notes include a link to the chat support board and a unique identifier that victims can use to contact the attackers.
See also: EnemyBot malware: Exploits critical VMware, F5 BIG-IP bugs
While not much is known about this new ransomware gang, it is likely not a new operation, but a rebranding, most likely of the Conti ransomware. This is evident from their proven ability to quickly breach new victims and the way they negotiate.
