Our latest Rapid7 Labs analysis undertakes a deep dive into Kyber #ransomware where we evaluated two Kyber ransomware payloads deployed in the same environment following an IR engagement. One targeting VMware ESXi infrastructure and the other Windows file servers providing us the opportunity to analyze both variants side by side. The results were interesting in that they differ in programming language they are written, crypto, and features. More details here: https://lnkd.in/e62bs7-z H/T Anna S. #malware #infosec
Kyber Ransomware Analysis: VMware ESXi and Windows File Servers
More Relevant Posts
-
Cybersecurity firm Rapid7 retrieved and analyzed two distinct Kyber variants in March 2026 during an incident response. Both variants were deployed on the same network, with one targeting VMware ESXi and the other focusing on Windows file servers. https://lnkd.in/ghAZKpuX
To view or add a comment, sign in
-
A new ransomware operation called Kyber is attacking Windows servers and VMware ESXi virtualisation systems — the software that runs multiple servers inside one physical machine. One variant claims to use post-quantum encryption (a new standard designed to resist future supercomputer attacks), though researchers found the claim is partly false. The only confirmed victim so far is a multi-billion-dollar American defence contractor. Both variants are designed to destroy every recovery path: deleting backups, wiping shadow copies (Windows automatic restore points), and disabling repair tools before demanding payment. 💀 #CyberNewsLive https://lnkd.in/gx2ydVRj
To view or add a comment, sign in
-
Kyber Ransomware Experiments with Post‑Quantum Encryption Overview A new Kyber ransomware campaign is targeting both Windows systems and VMware ESXi endpoints, with one variant experimenting with Kyber1024 post‑quantum encryption. Rapid7’s analysis in March 2026 revealed two distinct variants deployed simultaneously on the same victim network, suggesting the operator aimed to maximize impact by encrypting all servers at once. Key Highlights Targets: ESXi Variant…...
To view or add a comment, sign in
-
Kyber ransomware gang toys with post-quantum encryption on Windows. Cybersecurity firm Rapid7 retrieved and analyzed two distinct Kyber variants in March 2026 during an incident response. Both variants were deployed on the same network, with one targeting VMware ESXi and the other focusing on Windows file servers. https://lnkd.in/duASandA
To view or add a comment, sign in
-
Kyber ransomware now targets both Windows and ESXi, raising the risk of full operational shutdowns. Analysis found shared attacker infrastructure, while the ESXi sample overstates its post-quantum encryption claims. https://lnkd.in/eV3mBjUW
To view or add a comment, sign in
-
A new #Kyber #ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with one variant implementing Kyber1024 post-quantum encryption. #Cybersecurity firm Rapid7 retrieved and analyzed two distinct Kyber variants in March 2026 during an incident response. Both variants were deployed on the same network, with one targeting VMware #ESXi and the other focusing on Windows file servers. "The ESXi variant is specifically built for #VMware environments, with capabilities for datastore encryption, optional virtual machine termination, and defacement of management interfaces," explains #Rapid7. "The Windows variant, written in Rust, includes a self-described "experimental" feature for targeting Hyper-V." #news #BleepingComputer #InfoSec #InformationSecurity #PostQuantumCryptography https://lnkd.in/gs7f4m7Q
To view or add a comment, sign in
-
Kyber ransomware targets both VMware ESXi datastores and Windows file systems with shared Tor infrastructure, advanced encryption, and destructive anti-recovery features. Dual-platform threat evolves fast. #KyberRansomware #VMwareESXi #DataEncryption ➡️ https://ift.tt/RAK9FMh
To view or add a comment, sign in
-
-
A new Kyber ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with one variant implementing Kyber1024 post-quantum encryption. Cybersecurity firm Rapid7 retrieved and analyzed two distinct Kyber variants in March 2026 during an incident response. Both variants were deployed on the same network, with one targeting VMware ESXi and the other focusing on Windows file servers. "The ESXi variant is specifically built for VMware environments, with capabilities for datastore encryption, optional virtual machine termination, and defacement of management interfaces," explains Rapid7. https://lnkd.in/etv7-ePp #staycurious #stayinformed #noble1 #tomshaw TOM SHAW
To view or add a comment, sign in
-
Long lived, static credentials, that aren't in a TPM/HSM... shouldn't exist. There shouldn't be a reason for Hashicorp Vault to keep existing. APIs shouldn't be doing this anymore. Axios postmortem: https://lnkd.in/gKBMhBau / https://lnkd.in/gh8wtaRM (TL;DR; someone cloned an entire company, started a call, and a pop-up looked like their client software was out of date, installing a RAT on the machine) (Have you set up a YubiKey SSH key?) #CyberSecurity #BlueTeam #SupplyChain #SLSA
To view or add a comment, sign in
-
Kyber ransomware is now attacking two systems at once — the virtualisation infrastructure that runs entire company networks, and the Windows file servers holding business data. The attack is engineered for total operational shutdown: virtual machines are killed, datastores encrypted, and every backup and recovery option wiped before ransom demands appear. One in three ransomware attacks now involves a SonicWall device as the entry point. The payroll systems, medical records, and financial data your employer holds are increasingly running on exactly the infrastructure Kyber is designed to destroy completely. 💀 #CyberNewsLive https://lnkd.in/etF28bAA
To view or add a comment, sign in
Explore content categories
- Career
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Hospitality & Tourism
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development