HomeSecurityLinux version of TargetCompany ransomware targets VMware ESXi

Linux version of TargetCompany ransomware targets VMware ESXi

Researchers have observed a new Linux variant of the TargetCompany ransomware, which targets VMware ESXi environments using a custom shellto deliver and execute payloads.

See also: KVRT: Kaspersky's new tool for scanning and removing viruses on Linux

TargetCompany ransomware Linux

Also known as Mallox, FARGO , and Tohnichi , the TargetCompany ransomware operation emerged in June 2021 and has focused on database attacks (MySQL, Oracle, SQL Server) against organizations primarily in Taiwan, South Korea, Thailand, and India .

In February 2022, antivirus company Avast announced the availability of a free decryption tool that covered variants released up until that date. By September, however, the gang had resumed regular activity, targeting vulnerable Microsoft and threatening victims with leaking stolen data via Telegram.

New Linux variant

Cybersecurity firm Trend Micro says the new Linux variant of the TargetCompany ransomware ensures it has administrator privileges before continuing its malicious routine.

To download and execute the ransomware payload, the malicious actor uses a custom script that can also infiltrate data on two separate servers, possibly for redundancy in case of technical issues with the machine or in the event of a breach.

Once on the target system, the payload checks if it is running in a VMware ESXi environment by running the “uname” command and looking for “vmkernel”.

See also: Kimsuky team develops new Linux backdoor Gomir

A “ TargetInfo.txt ” file is then created and sent to the command and control (C2) server . It contains victim information such as hostname, IP address, operating system details, logged in users and permissions, unique identifiers, and details about the encrypted files and directories. The TargetCompany Linux version ransomware will encrypt files that have VM-related extensions ( vmdk, vmem, vswp, vmx, vmsn, nvram ), appending the “ .locked ” extension to the resulting files.

VMware ESXi

Finally, it displays a ransom note named “HOW TO DECRYPT.txt”, which contains instructions for the victim on how to pay the ransom and retrieve a valid decryption key.

After all tasks are completed, the shell script deletes the payload using the “rm -fx” command, so that all traces that can be used in post-event investigations are deleted from the affected machines.

Trend Micro analysts attribute the attacks deploying the new Linux variant of TargetCompany ransomware to a subsidiary called “vampire,” which is likely the same as a report by Sekoia last month.

The IP addresses used to deliver the payload and accept the text file with the victim's information were traced to an ISP in China. However, this is not enough to accurately determine the origin of the attacker.

Typically, TargetCompany ransomware focuses on Windows, but the release of the Linux variant and the shift to encrypting VMWare ESXi machines shows the evolution of the operation.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Ebury malware botnet has infected 400,000 Linux servers

Ransomware protection, such as TargetCompany’s new Linux release, is a critical aspect of cybersecurity that should be a priority for organizations and individuals. This form of malware encrypts a victim’s files, with the attacker demanding payment for the decryption key. Effective ransomware protection strategies include maintaining up-to-date antivirus software, regularly backing up data, and educating users on how to recognize phishing. Additionally, implementing multi-factor authentication and ensuring timely application of software patches can help mitigate vulnerabilities. Organizations should also consider using advanced threat detection systems to monitor and respond to suspicious activity in real time.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS