AvosLocker, a ransomware-as-a-service operation first identified targeting Windows systems, expanded to Linux with an ELF-based variant designed to hit VMware ESXi servers and disrupt virtualized environments. Reporting on the malware shows it was distributed through spam campaigns and exploitation of Microsoft Exchange ProxyShell-related flaws, then paired encryption with data theft and victim extortion through Tor-based leak sites and an affiliate program. The Linux strain, often called Avoslinux, accepts command-line parameters for thread count and target directories, checks for ESXi-related paths, and attempts to stop running virtual machines before encrypting files and appending the .avoslinux extension.
Technical analyses describe the Linux payload as a comparatively simple binary that prioritizes VM-related files such as .vmdk and .vmem, can invoke esxcli to kill active VMs, and may encrypt nearly all files on a host, including system files. Researchers found that the Linux variant uses embedded elliptic-curve cryptography with per-file symmetric keys and encrypted metadata appended to each file, while the Windows branch uses different routines including multithreading, network share enumeration, exclusion logic, and encryption that appends the .avos2 extension before dropping a ransom note. The combined findings show AvosLocker deliberately adapted its tooling to maximize impact against both traditional Windows networks and ESXi-based virtualization infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
VMware Security Blog published a technical analysis of AvosLocker's Linux variant, detailing its ESXi/VMFS targeting, VM shutdown behavior, encryption workflow, and ransom note. The post also released YARA detection logic, MITRE ATT&CK mappings, and file hashes for AvosLocker ELF samples and a decryptor.
The analyzed Avoslinux sample had been publicly available since January 2022. The Linux ransomware sample was later noted as found on MalwareBazaar.
AvosLocker operators announced a Linux variant of their ransomware in autumn 2021. The Linux branch was aimed at VMware ESXi environments.
AvosLocker was identified in 2021 as a ransomware-as-a-service operation. It initially targeted Windows systems before later expanding its tooling.
The reference states AvosLocker activity was observed in early July 2021, marking an early documented appearance of the ransomware family targeting business environments. The profile describes Windows-focused variants using AES-256 encryption and double-extortion style ransom demands.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
blog.lexfo.fr
Open sourceblog.qualys.com
Open sourceblogs.vmware.com
Open sourceblog.cyble.com
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.