Kaspersky reported that the Luna and Black Basta ransomware families rapidly advanced the trend toward cross-platform attacks, with both strains capable of targeting virtualized environments. Luna, written in Rust, was observed running on Windows, Linux, and ESXi and using an uncommon x25519 + AES encryption scheme, while its operators appeared to limit participation to Russian-speaking affiliates.
Black Basta, a newer C++ ransomware family, was described as maturing quickly and adding capabilities such as safe-mode reboot to improve execution and evade defenses. Kaspersky said the group had already claimed more than 40 victims across multiple sectors and regions, and noted that its Linux variant focused primarily on ESXi systems, reflecting a broader criminal shift toward encrypting virtualization infrastructure to maximize operational disruption.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By April 2022, Black Basta had added functionality to reboot infected Windows systems into safe mode before encryption and introduced persistence behavior mimicking Windows Services. Kaspersky noted these changes as signs of the ransomware's rapid maturation.
Black Basta first came to light in February 2022. At that stage, its malware, infrastructure, and campaign were still under development, with a victim website available but its victim blog not yet online.
Kaspersky analyzed a Linux version of Black Basta that was specifically designed to target ESXi systems, while also being capable of encrypting general Linux systems. The variant defaults to encrypting the /vmfs/volumes folder when no arguments are provided and uses ChaCha20 with multithreading to speed encryption.
Kaspersky analyzed Luna samples obtained via the Kaspersky Security Network and found the ransomware runs on Windows, Linux, and ESXi. The company also assessed with medium confidence that the operators are Russian speakers based on spelling mistakes in the embedded ransom note.
Kaspersky observed a new ransomware advertisement for Luna on a darknet ransomware forum. The advertisement stated that Luna worked only with Russian-speaking affiliates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.