Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireCybersecurity News

REvil ransomware group deploys Linux encryptor against EXSi virtual machines

cyber-security-freepik
June 30, 2021

The REvil ransomware operation have added a Linux encryptor to their arsenal that's designed to target and encrypt Vmware ESXi virtual machines.

BleepingComputer reports that security researcher MalwareHunterTeam found a Linux version of the REvil ransomware (aka Sodinokibi)) that also appears to target ESXi servers.

Advanced Intel's Vitali Kremez told BleepingComputer it is an ELF64 executable and includes the same configuration options utilized by the more common Windows executable. Kremez says this is the first know time the Linux variant has been publicly available since it was released.

Shawn Smith, Director of Infrastructure at nVisium, a Falls Church, Virginia-based application security provider, says, "The REvil update to support Linux broadens their attack vector tremendously; with a number of servers that are either Linux or based on Linux, they are no longer limited to a single operating system target and as such, can branch out into others easily. Attackers have already begun targeting virtual machines, such as the RegretLocker from last year."

According to Sean Nikkel, Senior Cyber Threat Intel Analyst at Digital Shadows, a San Francisco-based provider of digital risk protection solutions, "Within the last year, ESXi has been targeted by notable groups such as RansomEXX, DarkSide, Babuk Locker, and the former Maze group. Not to mention, adversaries have been attacking virtual machines for years prior to these incidents. If nothing else, it's a growth in capability for an already active and prolific group, with some interesting features."

Nikkel argues that it's possible other threat actors will continue to mirror these new developments to improve their craft. "A virtual machine typically has the same software running as a physical server, and if it's vulnerable, there's a good chance someone will exploit it. The good news is that VMware released updates for the most recent vulnerabilities disclosed in Spring 2021; however, adversaries are likely taking advantage of organizations that may be slow to patch," Nikkel says.

As organizations continue to modernize and become increasingly reliant on virtual machines and containerized systems, there will be an increase in attacks targeting these systems, and more specifically targeting the underlying infrastructure that they use to run, which in this case is ESXi, Smith explains.

Dirk Schrader, Global Vice President, Security Research at New Net Technologies (NNT), now part of Netwrix, explains that it should be no surprise that these attacks are directed against the market leader for virtualization, given the growth in its usage. "Another factor are the group of targets using the technology, mainly businesses with a path towards digitalization, that is a higher dependency and therefor a greater likelihood to pay a ransom," he says.

"This attack on the virtual machine infrastructure is a good reminder that new avenues of attack are being created every day, and if an attack doesn't exist today, it's still a real possibility tomorrow. Always keep proper backups and well-tested recovery plans so if an attack like this one targets your systems, you've at least got resilient BCP and DR plans to help recover, monitor and manage moving forward," Smith adds. 

Schrader says the best advice he can offer for organizations running ESXi environments is to, "check their exposure, validate all accounts having access to the environment, and closely monitor for any change happening."

 

 

 

KEYWORDS: cyber security encryption ransomware risk management security management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Soccer stadium

How the Current Iran-US Conflict May Impact World Cup Security

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Neighborhood

Residential AI Data Centers: Security, Privacy, and Governance Concerns

SEC 2026 Benchmark Banner

Events

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

LIVE: July 8, 2026 at 2 pm EDT In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • cybersecurity-freepik1170-x658x6.jpg

    Russian government arrests REvil ransomware gang members

    See More
  • ransomware freepik

    REvil ransomware sites are down

    See More
  • ransomware-attack-freepik

    DOJ charges REvil ransomware leaders with Kaseya attack

    See More

Related Products

See More Products
  • GSEC.jpg

    GSEC GIAC Security Essentials Certification All-In-One Exam Guide, 2E

See More Products

Events

View AllSubmit An Event
  • March 8, 2012

    iSecurity Virtual Tradeshow

    iSecurity is a FREE online event designed to put the information you need, the people you want to network with and the solution providers you want to hear from at your fingertips.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing