Kyber Ransomware Targets Windows and VMware ESXi Systems

Kyber Ransomware Targets Windows and VMware ESXi Systems

First seen 22 Apr 2026, 19:16 UTC SocprimeBleepingcomputerwww.rapid7.com 86% similarity 71.0

Article Content

Browse articles
ThreatCluster

The Kyber ransomware group has launched a coordinated attack targeting both Windows file servers and VMware ESXi systems. In March 2026, cybersecurity firm Rapid7 analyzed two variants of the ransomware deployed in the same environment, one for ESXi and the other for Windows. The ESXi variant is capable of encrypting datastore files, terminating virtual machines, and defacing management interfaces, while the Windows variant employs a hybrid encryption scheme involving post-quantum cryptography. Both variants share a common campaign ID and utilize Tor-based infrastructure for ransom demands. Rapid7 reported over 900 ransomware incidents in March 2026, highlighting the growing threat landscape. A notable victim identified is a multi-billion-dollar American defense contractor. The ransomware's encryption claims are misleading, as the ESXi variant primarily uses ChaCha8 and RSA-4096, while the Windows variant implements the advertised Kyber1024 scheme. Organizations are advised to enhance their defenses against these attacks.

Key Points: • Kyber ransomware targets both Windows and VMware ESXi systems with dual-platform variants. • The ESXi variant encrypts datastore files and defaces management interfaces, while the Windows variant uses post-quantum encryption. • A multi-billion-dollar defense contractor has been identified as a victim of the Kyber ransomware attacks.

ThreatCluster AI

Timeline

2026-03-01
Rapid7 analyzes two Kyber ransomware variants during incident response.
2026-03-15
Over 900 ransomware incidents reported in March 2026.
2026-04-22
Kyber ransomware attacks reported targeting Windows and ESXi systems.

Community

Browse all →