There's now a Linux version of this dangerous VMware ransomware

security
(Image credit: Shutterstock / binarydesign)

A ransomware operation known as Akira has been seen encrypting VMware ESXi virtual machines using a Linux encryptor after a couple of months of targeting Windows systems.

Major industries like education and finance have been in the crosshairs of the new ransomware, which has been encrypting stolen data from breached networks and marking compromised files with the .akira extension.

The double extortion attacks have seen some organizations receive demands to pay millions in return for their data, according to Bleeping Computer.

Akira ransomware could soon have even more victims

Twitter user rivitna is credited with discovering the Linux version of the ransomware, having shared screenshots on the social media platform alongside a sample of the Linux encryptor on VirusTotal.

Targeting VMware’s ESXi servers means that gangs can target more than one VM in a single hit, making it a potentially lucrative operation should the victims pay up.

Comparing this VMware ESXi encryptor with others analyzed by the publication, Bleeping Computer says that Akira's encryptors lack some advanced features, notably the automatic shutting down of VMs before encrypting files.

With the move to now threaten Linux users, more companies across the globe need to be on the lookout for signs of an attack, while simultaneously protecting their IT infrastructure from potential attacks.

According to a fresh Cyble report, 46 publicly disclosed victims have been announced since the attacks started in April 2023, with 33 located in the US.

Furthermore, the expansion to Linux is far from unique to Akira, with many ransomware attacks now looking to broaden their scope in the hopes of making them more lucrative.

Potential victims should conduct regular backups, update software as soon as it becomes available, and use trusted endpoint protection software. Those likely to have been affected by ransomware are being urged to take all measures possible to protect their data by removing external drives and detaching infected devices from their networks. 

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
A person holding out their hand with a digital AI symbol.
This ransomware gang is using SSH tunnels to target VMware appliances
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
AWS S3 feature abused by ransomware hackers to encrypt storage buckets
Close up of the Linux penguin.
A new Linux backdoor is hitting US universities and governments
Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business