New Play ransomware Linux version targets VMware ESXi VMs

Share:

Play ransomware is the latest ransomware gang to start deploying a dedicated Linux locker for encrypting VMware ESXi virtual machines.

Cybersecurity company Trend Micro, whose analysts spotted the new ransomware variant, says the locker is designed to first check whether it’s running in an ESXi environment before executing and that it can evade detection on Linux systems.

“This is the first time that we’ve observed Play ransomware targeting ESXi environments,” Trend Micro said.

“This development suggests that the group could be broadening its attacks across the Linux platform, leading to an expanded victim pool and more successful ransom negotiations.”

This has been a known trend for years now, with most ransomware groups shifting focus towards ESXi virtual machines after enterprises switched to using them for data storage and hosting critical applications due to their much more efficient resource handling.

Taking down an organization’s ESXi VMs will lead to major business operations disruptions and outages, while encrypting files and backups drastically reduces the victims’ options to recover impacted data.

While investigating this Play ransomware sample, Trend Micro also found that the ransomware gang uses the URL-shortening services provided by a threat actor tracked as Prolific Puma.

After successfully launching, Play ransomware Linux samples will scan and power off all VMs found in the compromised environment and start encrypting files (e.g., VM disk, configuration, and metadata files), adding the .PLAY extension at the end of each file.

To power off all running VMware ESXi virtual machines so that they can be encrypted, Trend Micro says the encryptor will execute the following code:

/bin/sh -c "for vmid in $(vim-cmd vmsvc/getallvms | grep -v Vmid | awk '{print $1}'); do vim-cmd vmsvc/power.off $vmid; done"

As BleepingComputer found while analyzing it, this variant is designed to specifically target VMFS (Virtual Machine File System), which is used by VMware’s vSphere server virtualization suite.

It will also drop a ransom note in the VM’s root directory, which will be displayed in the ESXi client’s login portal (and the console after the VM is rebooted).

Play ransomware surfaced in June 2022, with the first victims reaching out for help in BleepingComputer’s forums.

Its operators are known for stealing sensitive documents from compromised devices, which they use in double-extortion attacks to pressure victims into paying ransom under the threat of leaking the stolen data online.

High-profile Play ransomware victims include cloud computing company Rackspace, the City of Oakland in California, car retailer giant Arnold Clark, the Belgian city of Antwerp, and Dallas County.

In December, the FBI warned in a joint advisory with CISA and the Australian Cyber Security Centre (ACSC) that the ransomware gang had breached approximately 300 organizations worldwide until October 2023.

The three government agencies advised defenders to activate multifactor authentication wherever possible, maintain offline backups, implement a recovery plan, and keep all software up to date.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:59 pm, Jun 19, 2025
weather icon 23°C
L: 22° | H: 25°
scattered clouds
Humidity: 61 %
Pressure: 1025 mb
Wind: 11 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 34%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
22° | 25°°C 0 mm 0% 8 mph 61 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 27°°C 0 mm 0% 10 mph 71 % 1025 mb 0 mm/h
Sat Jun 21 10:00 pm
weather icon
18° | 32°°C 0 mm 0% 10 mph 60 % 1021 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
19° | 26°°C 0.69 mm 69% 15 mph 76 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
16° | 23°°C 0.2 mm 20% 14 mph 78 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 23°°C 0 mm 0% 8 mph 61 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
18° | 21°°C 0 mm 0% 7 mph 64 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 18°°C 0 mm 0% 6 mph 71 % 1024 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0 mm 0% 6 mph 65 % 1024 mb 0 mm/h
Tomorrow 10:00 am
weather icon
24° | 24°°C 0 mm 0% 8 mph 47 % 1024 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
27° | 27°°C 0 mm 0% 9 mph 35 % 1023 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 10 mph 35 % 1023 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 9 mph 41 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€90,862.06
-0.60%
Ethereum(ETH)
€2,184.43
-0.93%
Tether(USDT)
€0.87
0.00%
XRP(XRP)
€1.88
-0.19%
Solana(SOL)
€126.56
-1.30%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.147784
-0.17%
Shiba Inu(SHIB)
€0.000010
-1.33%
Pepe(PEPE)
€0.000009
-0.27%
Scroll to Top