Categories: News

Linux-based ransomware – Targets VMware servers

The new Linux-based ransomware targets VMware servers. Cheerscript implants double extortion malware on ESXi servers

Yes, the new one ransomware basato su Linux targeted servers VMware. Trend Micro researchers have discovered these “malware” which are used to attack VMware ESXi servers. These are a hypervisor bare-metal for creating and running several virtual machines (VM) that share the same hard disk storage space.

Cheerscrypt, the Linux-based ransomware

Is called Cheerscryptmalware that is following in the footsteps of other ransomware programs (click here for more information), such as LockBit, Hive e RansomEXXwho found ESXi an efficient way to infect many computers with malicious payloads at the same time.

Statements

Roger Grimesan advocate of defense and security awareness KnowBe4explains that most of the world’s organizations operate using virtual machines VMware.

It makes the work of ransomware attackers much easier because they can encrypt a server, the VMware server, and then encrypt every guest virtual machine it contains. A compromise and encryption command can easily encrypt tens to hundreds of other computers running virtually concurrently.

Grimes continues by adding that

Most virtual machine shops use one product to back up all guest servers. Then find and delete or damage a repository in backup“Kills” the backup for all guest servers that are connected at the same time.

How does it work?

Researchers from Trend Micro, Arianne Dela Cruz, Byron Gelera, McJustine De Guzman, explain in a corporate blog how it works Cheerscrypt. The malware, after acquiring an input parameter that specifies an encryption path, issues a command that terminates all processes in the VM to make sure it can encrypt all of its files.

The gang behind Cheerscrypt uses a technique of “double extortion”To extract money from its goals.

Security alarm !!!

declares the ransom message of the attackers, which continues with

We have successfully hacked your company. All files were stolen and encrypted by us. If you want to restore your files or avoid file loss, please contact us.

Encryption

The researchers note that Cheerscrypt uses the technology of public / private encryption to encrypt files on a target’s server. The ransomware’s executable file contains a public key, while the attacker holds the private key needed to decrypt the files. These are then encrypted using the stream code SOSEMANUKwhile ECDH it is used to create the SOSEMANUK key.

ESXi is a popular target for ransomware attacks. This is because, it is a means of quickly spreading ransomware to many devices at the same time.

As more and more organizations improve their security by adopting multi-factor authentication with biometricsthey are effectively blocking the front door for hackers,

he claims John Gunn, CEO of Tokenwhich however continues stating:

This doesn’t mean bad guys give up. Instead they will change their methods into attacks like this one.

And what do you think of this new Linux-based ransomware? Give us yours by leaving a comment below and continue to follow TechGameWorld.com to stay informed about the world of technology (and not only!).

Published by
Marco Dellapina

Recent Posts

F1, Miami GP: Racing Bulls unveils a special livery

In view of the sixth F1 round of the season which will stop in the…

8 hours ago

Salernitana-Atalanta: where to watch the match?

Different motivations but same objectives, score points. So let's find out where to watch Salernitana-AtalantaTelevision…

9 hours ago

Technology at the service of the user experience, the example of QuiGioco

Let's discover QuiGioco together, a new platform in the great universe of online casinos and…

9 hours ago

Amazon Prime Video: all the new releases of May 2024

Amazon Prime Video releases for May 2024: here are the films, shows and TV series…

12 hours ago

Anime Breakfast: Spy x Family Code White, una recensione tra spie e killer

In this new episode of Anime Breakfast, this time a review, let's find out together…

12 hours ago

Here is the new Ferrari livery for the Miami GP

Ferrari has finally revealed on its social channels the new look of the SF-24 that…

12 hours ago