Socprime
Kyber Ransomware Targets Windows and VMware ESXi Systems
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Kyber ransomware group has launched a coordinated attack targeting both Windows file servers and VMware ESXi systems. In March 2026, cybersecurity firm Rapid7 analyzed two variants of the ransomware deployed in the same environment, one for ESXi and the other for Windows. The ESXi variant is capable of encrypting datastore files, terminating virtual machines, and defacing management interfaces, while the Windows variant employs a hybrid encryption scheme involving post-quantum cryptography. Both variants share a common campaign ID and utilize Tor-based infrastructure for ransom demands. Rapid7 reported over 900 ransomware incidents in March 2026, highlighting the growing threat landscape. A notable victim identified is a multi-billion-dollar American defense contractor. The ransomware's encryption claims are misleading, as the ESXi variant primarily uses ChaCha8 and RSA-4096, while the Windows variant implements the advertised Kyber1024 scheme. Organizations are advised to enhance their defenses against these attacks.
Key Points: • Kyber ransomware targets both Windows and VMware ESXi systems with dual-platform variants. • The ESXi variant encrypts datastore files and defaces management interfaces, while the Windows variant uses post-quantum encryption. • A multi-billion-dollar defense contractor has been identified as a victim of the Kyber ransomware attacks.