{"id":157142,"date":"2023-02-06T11:23:28","date_gmt":"2023-02-06T17:23:28","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2023\/02\/linux-version-of-royal-ransomware-targets-vmware-esxi-servers"},"modified":"2023-02-06T11:23:28","modified_gmt":"2023-02-06T17:23:28","slug":"linux-version-of-royal-ransomware-targets-vmware-esxi-servers","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2023\/02\/linux-version-of-royal-ransomware-targets-vmware-esxi-servers","title":{"rendered":"Linux version of Royal Ransomware targets VMware ESXi servers"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/linux-version-of-royal-ransomware-targets-vmware-esxi-servers2.jpg\"><\/a><\/p>\n<p>Royal Ransomware is the latest ransomware operation to add support for encrypting Linux devices to its most recent malware variants, specifically targeting VMware ESXi virtual machines.<\/p>\n<p>BleepingComputer has been reporting on similar Linux ransomware encryptors released by multiple other gangs, including <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/linux-version-of-black-basta-ransomware-targets-vmware-esxi-servers\/\" target=\"_blank\">Black Basta<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/linux-version-of-lockbit-ransomware-targets-vmware-esxi-servers\/\" target=\"_blank\">LockBit<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/linux-version-of-blackmatter-ransomware-targets-vmware-esxi-servers\/\" target=\"_blank\">BlackMatter<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/linux-version-of-avoslocker-ransomware-targets-vmware-esxi-servers\/\" target=\"_blank\">AvosLocker<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomwares-new-linux-encryptor-targets-esxi-virtual-machines\/\" target=\"_blank\">REvil<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/linux-version-of-hellokitty-ransomware-targets-vmware-esxi-servers\/\" target=\"_blank\">HelloKitty<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ransomexx-ransomware-linux-encryptor-may-damage-victims-files\/\" target=\"_blank\">RansomEXX<\/a>, and <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hive-ransomware-now-encrypts-linux-and-freebsd-systems\/\" target=\"_blank\">Hive<\/a>.<\/p>\n<p>The new Linux Royal Ransomware variant was discovered by <a href=\"https:\/\/twitter.com\/BushidoToken\" target=\"_blank\" rel=\"nofollow noopener\">Will Thomas<\/a> of the Equinix Threat Analysis Center (ETAC), and is executed using the command line.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Royal Ransomware is the latest ransomware operation to add support for encrypting Linux devices to its most recent malware variants, specifically targeting VMware ESXi virtual machines. BleepingComputer has been reporting on similar Linux ransomware encryptors released by multiple other gangs, including Black Basta, LockBit, BlackMatter, AvosLocker, REvil, HelloKitty, RansomEXX, and Hive. The new Linux Royal [\u2026]<\/p>\n","protected":false},"author":396,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-157142","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/157142","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/396"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=157142"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/157142\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=157142"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=157142"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=157142"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}