Since ESXi servers host multiple virtual machines, which attract the threat actors most, a successful breach of these servers could enable threat actors to gain access to a multitude of valuable data and control over entire network environments.
Besides this, successful exploitation could enable them to simultaneously deploy ransomware across numerous systems and cause operational and financial damage to organizations.
Cybersecurity researchers at TrendMicro recently discovered that Play ransomware’s Linux variant has been actively attacking the ESXi servers.
A Linux variant of Play ransomware, targeting VMWare ESXi environments, was discovered by a threat-hunting team.
Following this development, it is possible that Play now attacks Linux systems, consequently making its potential victims more diverse.
Join our free webinar to learn about combating slow DDoS attacks, a major threat today.
It is malware that escapes detection and operates only if it detects the presence of an ESXi environment.
It also turns off the system for all VMs and alters the messages received after rebooting to make it appear that nothing has gone wrong, all through ESX-specific commands.
Consequently, it renames encrypted files with a .PLAY extension and leaves a ransom note behind.
This means that Play has adopted new strategies aimed at attacking mission-critical virtualization infrastructure, which has led to significant operational disruptions and complicated data recovery efforts.
An investigation into the hosting infrastructure of Play ransomware revealed ties to Prolific Puma. This cyber threat actor is reputed for selling link-shortening software to other internet threat actors.
The IP address that hosts the toolkit of Play ransomware resolves to domains matching the random domain generation algorithm (RDGA) pattern typical for Prolific Puma.
Further analysis on Coroxy, which is associated with Play, showed connections to IP addresses connected to Prolific Puma.
This demonstrates the possible use of a common network provider by both groups’ infrastructures, as they all share the same autonomous system number (ASN).
It consequently shows that there might be some collaboration between the two parties, and this implies that Prolific Puma may aid it in evading detection and spreading malware, which highlights the interconnectedness of threat actors.
Here below we have mentioned all the mitigations:-
Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…