HomeSecurityKraken ransomware: Targets Windows, Linux and VMware ESXi

Kraken ransomware: Targets Windows, Linux and VMware ESXi

In August 2025, a new cyber threat emerged on the global security landscape, radically changing the balance. The Kraken ransomware, a Russian-speaking cybercriminal ring, began launching large-scale attacks against organizations, proving that traditional defense strategies are no longer enough.

Kraken ransomware

Kraken's threat is not limited to the breadth of its targets, but rather its technological sophistication. It is one of the first ransomware to attempt comprehensive attacks on Windows, Linux, and VMware ESXi, leveraging specialized tools for each platform — a capability that has until now been primarily possessed by state-backed actors.

HelloKitty Ransomware Connection: An Old Team Returns

Investigations by several cybersecurity organizations indicate that Kraken did not start from scratch. There are indications that the group is a continuation or offshoot of the well-known HelloKitty ransomware operation , which had occupied international media attention in previous years.

See also: Ransomware: New groups emerge and LockBit returns

Similarities in payloads, file names, and even the structure of ransom notes reveal common roots.

A New Underground Forum for Cybercriminals

In September 2025, Kraken launched The Last Haven Board, a darknet hub designed to host communications, collaborations, and purchases between criminal groups.

The creation of such a platform shows that Kraken is not just aiming for profits through ransoms — it seeks to create an ecosystem. An environment within which it can expand its activity, recruit new partners, and trade data derived from breaches.

HelloKitty's support for Kraken on the new underground forum "The Last Haven Board" further strengthens the collaboration scenario.

See also: Chinese hackers abuse Anthropic's AI model Claude

Kraken ransomware: Targets Windows, Linux and VMware ESXi

Double Extortion Strategy and Multi-Stage Attacks

Cisco Talos analysts documented that Kraken is implementing a dual extortion tactic :

  1. Data theft and encryption ,
  2. Threat of publishing stolen files if payment is refused.

This model is becoming more common, as it increases pressure on victims and improves the chances of ransom payments.

The attack follows a strictly structured chain:

  • initial entry via SMB vulnerability on exposed servers,
  • theft of privileged credentials,
  • presence stabilization with RDP,
  • use Cloudflared for reverse tunnels,
  • data export via SSH Filesystem.

The level of organization demonstrates operational maturity and clear knowledge of the defense mechanisms of the companies.

Technical Arsenal: From Benchmarking to Adaptive Encryption

Before the ransomware activates encryption, it performs a highly unusual process: a speed test (benchmark) to calculate how fast it can operate without exhausting system resources, which would trigger immediate detection.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: New phishing campaign targets hotel customers

It then proceeds to attack using a combination of RSA-4096 and ChaCha20, two of the strongest encryption algorithms.

Command line options allow operators to configure:

  • the range of files to be encrypted,
  • the depth of the process,
  • delays that prevent detection.

For Windows, the typical command is in the form:
Encryptor.exe –key

The Linux and ESXi versions use ELF binaries with the ability to run in background mode (daemon) and support remote SSH connections for further automation.

Kraken intentionally avoids critical directories (e.g. Program Files) to keep the system operational — a tactic that allows negotiations to take place without completely collapsing the victim's environment.

See also: DoorDash: New data breach revealed

Kraken ransomware: Targets Windows, Linux and VMware ESXi

Why Kraken Worries Experts More Than Other Threats

Kraken is not just another ransomware. It is an ecosystem, an operational cybercrime platform , and an ever- evolving threat.

The combination of cross-platform capabilities, dark web collaboration infrastructure, and increased technical sophistication bodes well for the group's influence to grow in the coming months.

Experts warn that organizations must immediately reconsider their approach to cybersecurity, investing in:

  • multi-layered defense,
  • internal lateral movement monitoring,
  • zero trust architecture,
  • systematic patches to Internet-exposed services.

In a world where criminal groups now operate like businesses, the defenses of real businesses must evolve accordingly.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS