New Play ransomware Linux version targets VMware ESXi VMs

Teilen:

Play ransomware is the latest ransomware gang to start deploying a dedicated Linux locker for encrypting VMware ESXi virtual machines.

Cybersecurity company Trend Micro, whose analysts spotted the new ransomware variant, says the locker is designed to first check whether it’s running in an ESXi environment before executing and that it can evade detection on Linux systems.

“This is the first time that we’ve observed Play ransomware targeting ESXi environments,” Trend Micro said.

“This development suggests that the group could be broadening its attacks across the Linux platform, leading to an expanded victim pool and more successful ransom negotiations.”

This has been a known trend for years now, with most ransomware groups shifting focus towards ESXi virtual machines after enterprises switched to using them for data storage and hosting critical applications due to their much more efficient resource handling.

Taking down an organization’s ESXi VMs will lead to major business operations disruptions and outages, while encrypting files and backups drastically reduces the victims’ options to recover impacted data.

While investigating this Play ransomware sample, Trend Micro also found that the ransomware gang uses the URL-shortening services provided by a threat actor tracked as Prolific Puma.

After successfully launching, Play ransomware Linux samples will scan and power off all VMs found in the compromised environment and start encrypting files (e.g., VM disk, configuration, and metadata files), adding the .PLAY extension at the end of each file.

To power off all running VMware ESXi virtual machines so that they can be encrypted, Trend Micro says the encryptor will execute the following code:

/bin/sh -c "for vmid in $(vim-cmd vmsvc/getallvms | grep -v Vmid | awk '{print $1}'); do vim-cmd vmsvc/power.off $vmid; done"

As BleepingComputer found while analyzing it, this variant is designed to specifically target VMFS (Virtual Machine File System), which is used by VMware’s vSphere server virtualization suite.

It will also drop a ransom note in the VM’s root directory, which will be displayed in the ESXi client’s login portal (and the console after the VM is rebooted).

Play ransomware surfaced in June 2022, with the first victims reaching out for help in BleepingComputer’s forums.

Its operators are known for stealing sensitive documents from compromised devices, which they use in double-extortion attacks to pressure victims into paying ransom under the threat of leaking the stolen data online.

High-profile Play ransomware victims include cloud computing company Rackspace, the City of Oakland in California, car retailer giant Arnold Clark, the Belgian city of Antwerp, and Dallas County.

In December, the FBI warned in a joint advisory with CISA and the Australian Cyber Security Centre (ACSC) that the ransomware gang had breached approximately 300 organizations worldwide until October 2023.

The three government agencies advised defenders to activate multifactor authentication wherever possible, maintain offline backups, implement a recovery plan, and keep all software up to date.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:02 pm, Jan. 20, 2025
Wetter-Symbol 4°C
L: 1° | H: 5°
overcast clouds
Luftfeuchtigkeit: 90 %
Druck: 1017 mb
Wind: 5 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:54 am
Sonnenuntergang: 4:28 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
1° | 5°°C 0 mm 0% 4 mph 96 % 1017 mb 0 mm/h
Mi. Jan. 22 9:00 pm
Wetter-Symbol
4° | 5°°C 1 mm 100% 6 mph 97 % 1009 mb 0 mm/h
Do. Jan. 23 9:00 pm
Wetter-Symbol
3° | 8°°C 1 mm 100% 16 mph 90 % 1006 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
4° | 11°°C 1 mm 100% 24 mph 91 % 1005 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
2° | 5°°C 1 mm 100% 14 mph 94 % 1009 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 92 % 1017 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 94 % 1016 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 96 % 1015 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 92 % 1015 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 76 % 1015 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 3 mph 75 % 1012 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 4 mph 93 % 1011 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 94 % 1010 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€99,313.72
-1.13%
Ethereum(ETH)
€3,183.64
1.80%
XRP(XRP)
€3.00
0.61%
Fesseln(USDT)
€0.97
0.02%
Solana(SOL)
€238.19
-4.49%
Dogecoin(DOGE)
€0.344008
-5.08%
USDC(USDC)
€0.97
-0.01%
Shiba Inu(SHIB)
€0.000019
-1.94%
Pepe(PEPE)
€0.000016
-5.89%
Peanut das Eichhörnchen(PNUT)
€0.359173
-20.01%
Nach oben scrollen