Ransomware operators expanded Linux tooling to hit virtualization and storage infrastructure, with REvil and DarkSide both deploying ELF-based encryptors aimed at VMware ESXi hosts and NAS devices. Researchers linked REvil’s Linux samples to the group’s Windows operation through shared configuration traits, including a common RaaS affiliate ID and similarly encoded ransom notes, while noting that encrypting centralized hypervisors and storage can cause disproportionate disruption across enterprise environments.
Analysis of DarkSide’s Linux variant showed malware tailored for ESXi environments, including enumeration of host, storage, and vSAN details, termination of running virtual machines, and encryption of files under paths such as /vmfs/volumes/. The malware used ChaCha20 with RSA-4096, appended extensions such as .darkside, dropped darkside_readme.txt, and sent victim information to hard-coded command-and-control servers via HTTP POST. Separate tooling also emerged to extract and decode embedded configuration data from Linux REvil samples, exposing fields such as public keys, affiliate identifiers, campaign IDs, ransom-note filenames, and encrypted file extensions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A GitHub project named REconfig-linux was published to extract and decode embedded configuration data and ransom notes from ELF samples of the Linux REvil variant. The tool documented known configuration keys and stated it had been tested against four malware samples.
Threatpost reported that REvil operators had ported their ransomware to Linux to support targeted attacks against VMware ESXi environments and NAS devices. The report highlighted the operational impact of encrypting centralized VM storage and network-attached storage.
Trend Micro documented a Linux variant of DarkSide ransomware that targets VMware ESXi hosts and virtual machine-related files, including killing running VMs before encrypting data. The analysis also published technical details such as encryption behavior, C2 infrastructure, and sample hashes.
Alien Labs researcher Ofer Caspi said the Linux variant of REvil was spotted in May affecting Unix-like systems and VMware ESXi environments. This established that the Linux port was already being used in the wild.
AdvIntel reported in early May 2021 that REvil intended to port its Windows-based ransomware to Linux, indicating planned expansion beyond Windows targets.
The AlienVault reference states that DarkSide's developers announced they would be closing operations shortly after the Colonial Pipeline incident. This marked a major operational change for the ransomware-as-a-service group.
AT&T Cybersecurity's Alien Labs confirmed four Linux REvil samples after receiving a tip from MalwareHuntingTeam. The samples were described as ELF-64 executables sharing configuration traits and a RaaS affiliate ID with Windows REvil variants.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
otx.alienvault.com
Open sourcegithub.com
Open sourcethreatpost.com
Open sourcetrendmicro.com
Open sourcecybersecurity.att.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.