Latest Daily News Hosting, Technology News, Updates, and Trends
Latest Daily News Hosting, Technology News, Updates, and Trends
  • Home
  • News Categories
    • Cyber Security
    • Cloud Hosting
    • Data Center
    • WordPress
    • Search Engine Ranking
    • cPanel Hosting
    • CDN Hosting
    • Press Release
    • WordPress.org-Wp Engine Battle
    • World
  • Web Stories
 New Linux-Based Variant For AvosLocker Ransomware Aims At VMware ESXi Servers
Cyber Security

New Linux-Based Variant For AvosLocker Ransomware Aims At VMware ESXi Servers

by Manvinder Singh January 13, 2022 0 Comment

AvosLocker, an emerging ransomware gang has added Linux system encryption to extend its latest malware variants. The recent variants are suspected to target VMware ESXi virtual machines.

The actual victims of the Linux variant of the AvosLocker Ransomware are however still unidentified. According to BleepingComputer, “While we couldn’t find what targets were attacked using this AvosLocker ransomware Linux variant, we know of at least one victim that got hit with a $1 million ransom demand.”

The Incidence

In November 2021, the AvosLocker gang revealed their latest ransomware variants, AvosLinux and Windows Avos2 while warning affiliates against attacking CIS/post-soviet websites.

In their advertisement, they wrote, “Avos2 / Avoslinux has the best of both worlds: High performance and high amount of encryption compared to its competitors”.

Other ransomware operations that support Linux and ESXi servers are Mespinoza, Babuk, HelloKitty, and RansomExx/Defray. The Linux variants of renowned ransomware enable intruder gangs to target a wide range of organizations, specifically those using ESXi servers.

How The Ransomware Gang Works

When AvosLocker gets installed on a compromised Linux system, it wiill run the following command:

esxcli –formatter=csv –format-param=fields==”WorldID,DisplayName” vm process list | tail -n +2 | awk -F $’,’ ‘{system(“esxcli vm process kill –type=force –world-id=” $1)}’

This command aims to shut down all ESXi machines on the server. Further, the ransomware will affix the .avoslinux extension to all encrypted files. The AvosLocker gang leaves ransom notes warning the victims not to shut down their systems to prevent file damage. The victims are further instructed to visit a TOR (onion) site for further information on how to pay the ransom.

Image Source: BleepingComputer

AvosLocker is a new gang that first emerged in the threat landscape during the summer of 2021. Initially, it called for ransomware affiliates to join their Ransomware-as-a-Service (RaaS) operation.

In December, the ransomware gang accidentally hit a US government entity. Fearing the police, it released a free decryptor to prevent any loss to the government authorities.


If you enjoyed this post, you will undoubtedly enjoy this one as well –

  • Microsoft Released Emergency Fix for Remote Desktop Issues in Windows Server
  • AWS Prolonged Outage Brings Internet At A Standstill
  • GoDaddy Data Leak Hints Users Trust Is At Stake
  • Rubrik Announces Azure-based New Data & Security Ransomware



Tags: Linux system encryption Linux Variant Linux-Based Variant For AvosLocker VMware ESXi virtual machines
Previous post
Next post

Manvinder Singh (Website)

author

Manvinder Singh, with 15 years in the web hosting industry, now shares his expertise as a news auditor, enriching web hosting users with valuable insights and guidance. His extensive experience spans server management, security protocols, and customer support, making him a trusted source in navigating the complexities of web hosting solutions. Passionate about transparency and reliability, Manvinder continues to empower businesses and individuals with practical knowledge, ensuring they make informed decisions in optimizing their online presence.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent News

  • CITRA to Sign Lease Contract with Google to Establish Three Data Centers  
  • Last Algorithm Update of 2024; Google Rolls Out December Core Update
  • WP Engine Scores Legal Win Against Automattic
  • Search Engine Update: Google Resolved Indexing Issues
  • Google Asks US Government to Break Up Microsoft’s Cloud Deal with Open AI

Recent Comments

No comments to show.

Archives

  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • October 2022
  • September 2022
  • August 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021

Categories

  • Cloud Hosting
  • cPanel Hosting
  • Cyber Security
  • Data Center
  • Press Release
  • Search Engine Ranking
  • WordPress
  • WordPress.org-Wp Engine Battle
  • World

About Hosting Daily News

Hosting Daily news primarily focuses on delivering quality and authentic content related to the hosting industry. Hosting Daily News covers a wide range of news, articles, announcements, community-based content to keep the tech enthusiasts engaged with the latest development of hosting industry which includes Cloud Hosting, Web Hosting, cybersecurity, WordPress, AI technology and various topics related to hosting. We aim to foster collaborations and knowledge sharing content among industry stakeholders.

Top Categories

  • Cloud Hosting
  • cPanel Hosting
  • Cyber Security
  • Data Center
  • Press Release
  • Search Engine Ranking
  • WordPress
  • WordPress.org-Wp Engine Battle
  • World

Latest News

  • CITRA to Sign Lease Contract with Google to Establish Three Data Centers  
  • Last Algorithm Update of 2024; Google Rolls Out December Core Update
  • WP Engine Scores Legal Win Against Automattic
  • Search Engine Update: Google Resolved Indexing Issues
  • Google Asks US Government to Break Up Microsoft’s Cloud Deal with Open AI
Copyright © 2025 HostingDailyNews. All Right Reserved.
  • Instagram
  • Facebook
  • X
  • LinkedIn