New Play ransomware Linux version targets VMware ESXi VMs

Share:

Play ransomware is the latest ransomware gang to start deploying a dedicated Linux locker for encrypting VMware ESXi virtual machines.

Cybersecurity company Trend Micro, whose analysts spotted the new ransomware variant, says the locker is designed to first check whether it’s running in an ESXi environment before executing and that it can evade detection on Linux systems.

“This is the first time that we’ve observed Play ransomware targeting ESXi environments,” Trend Micro said.

“This development suggests that the group could be broadening its attacks across the Linux platform, leading to an expanded victim pool and more successful ransom negotiations.”

This has been a known trend for years now, with most ransomware groups shifting focus towards ESXi virtual machines after enterprises switched to using them for data storage and hosting critical applications due to their much more efficient resource handling.

Taking down an organization’s ESXi VMs will lead to major business operations disruptions and outages, while encrypting files and backups drastically reduces the victims’ options to recover impacted data.

While investigating this Play ransomware sample, Trend Micro also found that the ransomware gang uses the URL-shortening services provided by a threat actor tracked as Prolific Puma.

After successfully launching, Play ransomware Linux samples will scan and power off all VMs found in the compromised environment and start encrypting files (e.g., VM disk, configuration, and metadata files), adding the .PLAY extension at the end of each file.

To power off all running VMware ESXi virtual machines so that they can be encrypted, Trend Micro says the encryptor will execute the following code:

/bin/sh -c "for vmid in $(vim-cmd vmsvc/getallvms | grep -v Vmid | awk '{print $1}'); do vim-cmd vmsvc/power.off $vmid; done"

As BleepingComputer found while analyzing it, this variant is designed to specifically target VMFS (Virtual Machine File System), which is used by VMware’s vSphere server virtualization suite.

It will also drop a ransom note in the VM’s root directory, which will be displayed in the ESXi client’s login portal (and the console after the VM is rebooted).

Play ransomware surfaced in June 2022, with the first victims reaching out for help in BleepingComputer’s forums.

Its operators are known for stealing sensitive documents from compromised devices, which they use in double-extortion attacks to pressure victims into paying ransom under the threat of leaking the stolen data online.

High-profile Play ransomware victims include cloud computing company Rackspace, the City of Oakland in California, car retailer giant Arnold Clark, the Belgian city of Antwerp, and Dallas County.

In December, the FBI warned in a joint advisory with CISA and the Australian Cyber Security Centre (ACSC) that the ransomware gang had breached approximately 300 organizations worldwide until October 2023.

The three government agencies advised defenders to activate multifactor authentication wherever possible, maintain offline backups, implement a recovery plan, and keep all software up to date.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
7:37 am, Jan 21, 2025
weather icon 2°C
L: 1° | H: 3°
fog
Humidity: 95 %
Pressure: 1015 mb
Wind: 2 mph WNW
Wind Gust: 3 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 9 km
Sunrise: 7:53 am
Sunset: 4:29 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
1° | 3°°C 0 mm 0% 4 mph 95 % 1015 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
4° | 5°°C 1 mm 100% 5 mph 97 % 1009 mb 0 mm/h
Thu Jan 23 9:00 pm
weather icon
2° | 9°°C 1 mm 100% 17 mph 93 % 1008 mb 0 mm/h
Fri Jan 24 9:00 pm
weather icon
6° | 11°°C 1 mm 100% 24 mph 90 % 1006 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
2° | 6°°C 1 mm 100% 12 mph 99 % 1013 mb 4.43 mm/h
Today 9:00 am
weather icon
2° | 3°°C 0 mm 0% 2 mph 95 % 1015 mb 0 mm/h
Today 12:00 pm
weather icon
3° | 5°°C 0 mm 0% 4 mph 89 % 1015 mb 0 mm/h
Today 3:00 pm
weather icon
4° | 6°°C 0 mm 0% 3 mph 81 % 1013 mb 0 mm/h
Today 6:00 pm
weather icon
4° | 4°°C 0 mm 0% 3 mph 82 % 1012 mb 0 mm/h
Today 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 3 mph 91 % 1011 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 4°°C 0 mm 0% 3 mph 95 % 1009 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 3 mph 96 % 1007 mb 0 mm/h
Tomorrow 6:00 am
weather icon
4° | 4°°C 0.84 mm 84% 3 mph 96 % 1005 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€98,198.00
-5.53%
Ethereum(ETH)
€3,125.58
-3.41%
XRP(XRP)
€2.96
-3.85%
Tether(USDT)
€0.96
0.01%
Solana(SOL)
€227.47
-8.16%
Dogecoin(DOGE)
€0.329563
-8.54%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000019
-7.04%
Pepe(PEPE)
€0.000014
-11.53%
Peanut the Squirrel(PNUT)
€0.354320
-12.00%
Scroll to Top