BTC $66157.0605
ETH $3160.9620
BNB $600.0523
SOL $153.7382
XRP $0.5487
stETH $3158.2980
DOGE $0.1576
TON $5.5645
ADA $0.5086
AVAX $38.3049
wstETH $3680.0518
WBTC $66253.4640
DOT $7.3621
WETH $3160.3315
TRX $0.1121
BCH $509.2779
LINK $15.3526
MATIC $0.7263
UNI $8.0690
ICP $14.6066
LTC $84.3899
DAI $0.9987
CAKE $2.9756
RNDR $9.0447
IMX $2.3823
STX $3.0517
NEAR $6.8843
ETC $27.8833
FDUSD $1.0002
MNT $1.1936
FIL $6.4625
TAO $503.6116
OKB $54.7164
HBAR $0.0881
VET $0.0418
KAS $0.1270
ATOM $8.7670
PEPE $0.0000
GRT $0.2943
WIF $2.7575
FET $2.4107
MKR $2818.4937
INJ $27.8130
USDE $0.9992
THETA $2.3518
XLM $0.1162
CORE $2.5749
BTC $66157.0605
ETH $3160.9620
BNB $600.0523
SOL $153.7382
XRP $0.5487
stETH $3158.2980
DOGE $0.1576
TON $5.5645
ADA $0.5086
AVAX $38.3049
wstETH $3680.0518
WBTC $66253.4640
DOT $7.3621
WETH $3160.3315
TRX $0.1121
BCH $509.2779
LINK $15.3526
MATIC $0.7263
UNI $8.0690
ICP $14.6066
LTC $84.3899
DAI $0.9987
CAKE $2.9756
RNDR $9.0447
IMX $2.3823
STX $3.0517
NEAR $6.8843
ETC $27.8833
FDUSD $1.0002
MNT $1.1936
FIL $6.4625
TAO $503.6116
OKB $54.7164
HBAR $0.0881
VET $0.0418
KAS $0.1270
ATOM $8.7670
PEPE $0.0000
GRT $0.2943
WIF $2.7575
FET $2.4107
MKR $2818.4937
INJ $27.8130
USDE $0.9992
THETA $2.3518
XLM $0.1162
CORE $2.5749
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • New Linux version of Royal Ransomware targets ESXi Virtual Machines


    Cybersecurity researcher Will Thomas of the Equinix Threat Intelligence Center (ETAC) has discovered that the Royal Ransomware has added Linux device encryption support to its latest malware variants that target VMware ESXi virtual machines.

    The new variant of Royal Ransomware is executed via the command line and supports several flags that will give the operator partial control over the encryption process:

    • -stopvm - stops all running virtual machines so that they can be encrypted;
    • -vmonly - encrypt only virtual machines;
    • -fork - unknown;
    • -logs - unknown;
    • -id - ID of 32 characters.

    When encrypting files, the ransomware will add the ".royal_u" extension to all encrypted files in the virtual machine. Previously, antivirus solutions were previously unable to detect the new Royal Ransomware sample, but now it is detected by 23 out of 62 scan engines on VirusTotal.

    The shift of ransomware groups towards ESXi virtual machines is due to enterprises moving to virtual machines, as they provide better device management and more efficient resource handling. Once payloads are deployed to ESXi hosts, ransomware operators use a single command to encrypt multiple servers.

    Author DeepWeb
    Mustang Panda uses interesting bait in its new malware campaign
    Fentanyl

    Comments 0

    Add comment