A recently discovered sample of the Qilin ransomware group's VMware ESXi encryptor may be one of the most advanced and customized Linux encryptors to date.
See also: Over 40 countries to sign to stop paying ransoms to ransomware gangs

Businesses are increasingly switching to virtual machines to host their servers , as these allow better use of available CPU, memory, and storage resources .
Due to this adoption, almost all ransomware gangs have created dedicated VMware ESXi encryptors to attack these servers.
Many ransomware operations use leaked Babuk code to create their own ciphers, while some, like Qilin, create their own ciphers to attack Linux servers.
Last month, security firm MalwareHunterTeam discovered a Linux ELF64 from the Qilin ransomware group and shared it with BleepingComputer for analysis.
Although the cryptographer can be used on Linux, FreeBSD, and VMware ESXi servers, it is primarily focused on encrypting virtual machines and deleting their snapshots.
Qilin Encryptor is built with a built-in configuration that specifies the extension for encrypted files, processes to be terminated, files to be encrypted or blocked, and folders to be encrypted or blocked. However, it also includes multiple command line parameters that allow for extensive customization of these configuration options and how files are encrypted on a server.
These command line arguments include options to enable mode , perform a test run without file encryption, or customize how virtual machines and their backups are encrypted.
See also: Internal messages of the Conti ransomware gang leaked

The Qilin ransomware operation was originally operating under the name “Agenda” since August 2022. However, by September, it had rebranded itself as Qilin, under which it continues to operate to this day.
Like other ransomware attacks targeting businesses, Qilin will breach a company's networks and steal data as it spreads laterally to other systems.
After collecting the data and obtaining the server administrator credentials, the threat actors install ransomware to encrypt all devices on the network. The stolen information and encrypted files are then used as leverage in double-blackmail attacks to force a company to pay a ransom.
Since its inception, the ransomware operation has recorded a steady stream of victims, but increased activity was observed towards the end of 2023.
Recently, Qilin carried out an attack on the automobile giant Yanfeng.
The main victims of Qilin ransomware are organizations and businesses operating in critical sectors such as banking, healthcare, and government. These organizations often hold sensitive data and are the target of Qilin ransomware attacks.
Small and medium-sized businesses are also often victims of Qilin ransomware. These businesses may not have the same resources to effectively deal with attacks and may be more vulnerable to data loss and financial losses.
Additionally, individuals using personal computers and the internet can also be victims of Qilin ransomware. These attacks may target individuals who hold important personal data, such as photos, files, and personal information, with the aim of obtaining a ransom to decrypt their data.
See also: Ransomware gangs are changing tactics and ransoms are increasing!
Finally, government entities may also be victims of Qilin ransomware. These attacks may have political objectives, aiming to disrupt government systems and cause disruption.
Source: bleepingcomputer
