Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure
A threat actor operating under the handle EclipseSupport is actively promoting a new Ransomware-as-a-Service (RaaS) operation named Eclipse Ransomware on cybercrime forums.
The group is recruiting cybercrime affiliates, claiming its platform can compromise a wide spectrum of enterprise systems, including Windows, Linux servers, NAS storage appliances, VMware ESXi hypervisors, and Nutanix virtualized infrastructure.
Unlike traditional single-OS malware, Eclipse Ransomware is engineered from the ground up as a multi-platform deployment.
The Windows payload is written in Rust, leveraging the language’s memory-safety, performance, and evasion characteristics, while the variants targeting Linux, NAS devices, ESXi, and Nutanix environments are developed in C++.
This dual-codebase approach allows the operators to effectively target hybrid enterprise environments, virtualized cloud workloads, and on-premises data centers.
The emergence of cross-platform encryptors mirrors a growing industry trend seen across other RaaS platform models designed to maximize impact across diverse server fleets.
The malware operators claim that Eclipse Ransomware utilizes ChaCha20 symmetric encryption paired with Kyber-based post-quantum cryptographic key exchange mechanisms.
Affiliates are offered configurable encryption modes to balance operational speed against stealth, helping ensure file locking finishes before local security tools respond.
As spotted by DarkWebInformer, the platform includes specific routines designed to encrypt Hyper-V virtual machines and disable Veeam backup infrastructure.
Neutralizing backup repositories and hypervisor stores is a high-value tactic intended to prevent organizations from performing clean system restores.
For Windows domain environments, the platform allegedly embeds automated features for:
Targeting hypervisors allows threat actors to execute high-impact VMware ESXi attacks, crippling hundreds of virtual servers simultaneously.
Eclipse Ransomware operates as a fully managed affiliate ecosystem. The administrative web panel provides centralized campaign controls, multi-user team access, automated payment validation, real-time activity logging, and an integrated LiveChat portal to handle victim ransom negotiations directly.
| Management Feature | Technical Implementation |
| Payment Options | Separate Bitcoin (BTC) and Monero (XMR) wallets per target |
| Anonymity Layer | Dedicated Tor .onion negotiation addresses generated for each victim |
| Data Extortion | Direct leak-site publishing options embedded in the affiliate panel |
| Future Modules | Automated cloud/tape backup targeting, data exfiltration, and FreeBSD/OpenBSD builds |
The developers leverage double extortion tactics, threatening to publish stolen corporate data on dedicated leak sites if victims refuse to pay the decryption ransom.
To attract experienced affiliates, EclipseSupport is offering an introductory 90/10 revenue split in favor of the affiliate for their first 10 successful extortion cases, after which the split adjusts to a standard 80/20 ratio.
Applicants are required to pay a $300 entry fee—which the operators claim is fully refundable upon the affiliate’s first successful ransom payout—and must target organizations with an expected payout threshold of at least $70,000.
Affiliates are strictly forbidden from submitting ransomware samples to VirusTotal or public multi-scanner portals.
While the claims made by EclipseSupport have not been independently verified in wild intrusions, security teams should proactively harden enterprise networks:
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…