216.73.216.226

Kyber Ransomware Double Trouble: Windows and ESXi Attacks Explained

· Published 22/04/2026 12:39 · Modified 22/04/2026 15:32

Export JSON

Essential information

Published
22/04/2026 12:39
Modified
22/04/2026 15:32
Tags
2026-04-22 chacha8 cross-platform esxi hyper-v kyber rust virtualization vmware
Related entities
3 observables, 1 intrusion sets (apt), 19 techniques (mitre), 1 malware

Description

ransomware represents a significant threat through dual-platform deployment capabilities targeting infrastructure and Windows file systems. During a March 2026 incident response engagement, two payloads were recovered from the same environment. The variant, written in C++, specifically targets environments with datastore encryption, VM termination, and management interface defacement capabilities. The Windows variant, written in , includes experimental targeting features. Both samples share campaign identifiers and Tor-based infrastructure, confirming coordinated operations. Despite advertising post-quantum Kyber1024 encryption, the variant actually uses with RSA-4096 key wrapping, while the Windows variant implements the claimed AES-256-CTR with Kyber1024 hybrid scheme. The ransomware includes anti-recovery measures, service termination, and effective encryption strategies designed to cause complete operational disr...

External references