Linux Variant of REvil Ransomware Targets VMware’s ESXi, NAS Devices
#1
Information 
Quote:Cybercriminals behind a string of high-profile ransomware attacks, including one extorting $11 million from JBS Foods last month, have ported their malware code to the Linux operating system. The unusual move is an attempt to target VMware’s ESXi virtual machine management software and network attached storage (NAS) devices that run on the Linux operating system (OS).
 
Researchers at AT&T Cybersecurity said they have confirmed four Linux samples of the REvil malware in the wild.
 
Ofer Caspi, security researcher at Alien Labs, a division of AT&T Cybersecurity, wrote in a Thursday blog that after receiving a tip from MalwareHuntingTeam it identified the four samples.
 
“REvil ransomware authors have expanded their arsenal to include Linux ransomware, which allows them to target ESXi and NAS devices,” Caspi wrote.
 
In a nod to research by AdvIntel in early May 2021, which reported REvil’s intent to port its Windows-based ransomware to Linux, Caspi confirmed the Linux variant was spotted in May “affecting *nix systems and ESXi.”
 
“The samples are ELF-64 executables, with similarities to the Windows REvil executable, being the most noticeable among the configuration options,” he wrote.
 
Executable and Linkable Format (or ELF-64) is a standard file format for executable files within Linux and UNIX-like operating systems, according to a technical breakdown.

Read more: Linux Variant of REvil Ransomware Targets VMware’s ESXi, NAS Devices | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Linux Variant of REvil Ransomware Targets VMware’s ESXi, NAS Devices - by silversurfer - 02 July 21, 18:05

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
uBOLite 2026.614.1502 (already available...
uBOLite 2026.614.1...harlan4096 — 08:59
Sandboxie 1.17.8 / 5.72.8
Sandboxie Plus 1.1...harlan4096 — 15:53
Brave 1.91.172 (Jun 12, 2026)
Release Notes v1.9...harlan4096 — 11:13
AdGuard VPN for Windows 2.9.3
AdGuard VPN for Wi...harlan4096 — 11:12
Microsoft Edge 149.0.4022.69
Version 149.0.4022...harlan4096 — 11:11

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>