IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Linux-based Cheerscrypt ransomware found targeting VMware ESXi servers

Cheerscrypt malware could cause severe disruption to companies using the virtualisation software

A smartphone, lying on its side in front of a data graphic, with the word VMware displayed

Security researchers have discovered new ransomware targeting vulnerable VMware ESXi servers.

Dubbed “Cheers” or “Cheerscrypt”, the ransomware first hijacks an ESXi server, then launches an encryptor that locates virtual machines and then terminates them with an esxcli command, according to the researchers at Trend Micro.

In a blog post, researchers said the termination of the VM processes ensures that the ransomware can successfully encrypt VMware-related files. They added that this ransomware is similar to ransomware families such as LockBitHive, and RansomEXX, which have attacked other ESXi servers in the past.

The Cheers ransomware looks for files with the following filename extensions: .log, .vmdk, .vmem, .vswp, and .vmsn. These file types are connected to ESXi snapshots, log files, swap files, paging files, and virtual disks.

Before encryption occurs, the ransomware will rename each file in a directory to a .Cheers extension, and will add a ransom note, titled 'How to Restore your Files.txt, alongside these. The researchers noted that the encryption fails if access permission for the file was not granted.

Following encryption, it displays a console that contains the data statistics of its attack, including how many files have been encrypted, and how many have been skipped.

The malware’s executable file contains the public key of a matching key pair with the private key being held by the hackers. It uses the SOSEMANUK stream cypher to encrypt files and ECDH to generate the SOSEMANUK key.

An ECDH public-private key pair is encrypted on the machine through Linux’s /dev/urandom. It then uses the embedded public key and the generated private key to create a secret key, that will be used as a SOSEMANUK key.

According to researchers, decryption is only possible if the malicious actor’s private key is known.

Researchers said that ESXi is a popular target for ransomware attacks. “Compromising ESXi servers has been a scheme used by some notorious cybercriminal groups because it is a means to swiftly spread the ransomware to many devices. Organizations should thus expect malicious actors to upgrade their malware arsenal and breach as many systems and platforms as they can for monetary gain,” they added.

The research comes a week after US security agency CISA warned federal and private organisations to urgently patch or remove five vulnerable VMware products that were being actively targeted by hackers.

Featured Resources

Accelerating AI modernisation with data infrastructure

Generate business value from your AI initiatives

Free Download

Recommendations for managing AI risks

Integrate your external AI tool findings into your broader security programs

Free Download

Modernise your legacy databases in the cloud

An introduction to cloud databases

Free Download

Powering through to innovation

IT agility drive digital transformation

Free Download

Recommended

Broadcom formally confirms $61 billion acquisition of VMware
mergers and acquisitions

Broadcom formally confirms $61 billion acquisition of VMware

26 May 2022
Broadcom reportedly looking at acquiring cloud company VMware
mergers and acquisitions

Broadcom reportedly looking at acquiring cloud company VMware

23 May 2022
US security agency issues emergency alert over vulnerable VMware products
Security

US security agency issues emergency alert over vulnerable VMware products

19 May 2022
Unlocking the value of data with data innovation acceleration
Whitepaper

Unlocking the value of data with data innovation acceleration

12 May 2022

Most Popular

FCC commissioner urges Apple and Google to remove TikTok from app stores
data protection

FCC commissioner urges Apple and Google to remove TikTok from app stores

29 Jun 2022
Former Uber security chief to face fraud charges over hack coverup
data breaches

Former Uber security chief to face fraud charges over hack coverup

29 Jun 2022
Internet providers look to ease cost of living crisis with cheaper broadband
broadband

Internet providers look to ease cost of living crisis with cheaper broadband

29 Jun 2022