Summary:
Researchers recently discovered a Linux sample performing Ransomware operations. The sample was identified as a Linux variant of Royal ransomware that targets ESXi servers. Ransomware is mostly targeting the Manufacturing industries. Royal ransomware had emerged as the most prevalent ransomware. The threat actor is using phishing emails to spread the Royal Ransomware. Following successful execution, the payload, and all files get appended with ".royal u" in the extension and drop a ransom note named "readme.txt”.[/subscribe_to_unlock_form]
Summary:
Researchers recently discovered a Linux sample performing Ransomware operations. The sample was identified as a Linux variant of Royal ransomware that targets ESXi servers. Ransomware is mostly targeting the Manufacturing industries. Royal ransomware had emerged as the most prevalent ransomware. The threat actor is using phishing emails to spread the Royal Ransomware. Following successful execution, the payload, and all files get appended with ".royal u" in the extension and drop a ransom note named "readme.txt”.[emaillocker id="1283"]

Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]