Scworld
Ransomware Operators Exploit ISPsystem VMs for Malicious Payloads
First seen 6 Feb 2026, 22:23 UTC
•
•92% similarity
•53.7
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Ransomware operators are leveraging virtual machines (VMs) provided by ISPsystem to host and distribute malicious payloads. Cybersecurity researchers at Sophos identified this tactic during their investigation of recent 'WantToCry' ransomware incidents, noting the use of Windows VMs with identical hostnames, indicative of default templates from ISPsystem's VMmanager.
ThreatCluster AI
How this analysis works