Sophos Ransomware Protection

New Python-Based Ransomware Attack Targets VMware ESXi Servers

 

A new and highly aggressive Python-based ransomware variant has emerged, with cybersecurity experts warning businesses to strengthen their defences, particularly those using VMware ESXi servers.

On October 5, 2021, Sophos reported a sophisticated ransomware attack that took only 10 minutes to execute once the attacker gained access via a compromised TeamViewer account. The malware was used to shut down and encrypt virtual machines hosted on an ESXi server. This highlights critical vulnerabilities in remote access tools and virtual infrastructure.

 

How the Ransomware Attack Happened

The attack began when cybercriminals breached a TeamViewer session, which was running on a machine linked to a user with domain administrator credentials. From 12:30 am to 12:40 am, attackers quickly escalated their privileges and targeted the company’s VMware ESXi environment.

 

Key Points of Entry:

  • TeamViewer, a remote desktop control tool, was the initial vector
  • The attacker exploited an enabled ESXi Shell, which had been left active
  • Bitvise SSH Client was installed to access and control the ESXi hypervisor
  • Python-based malware was deployed directly onto the ESXi server

VMware ESXi is a bare-metal hypervisor widely used to run and manage virtual machines. In this incident, it was exploited because an administrative oversight left its SSH shell enabled, creating an open pathway for threat actors.

 

What the Ransomware Did

Once inside the ESXi server, the attackers launched a Python ransomware script, just 6KB in size but highly effective. The malware performed the following actions:

  • Scanned and mapped all virtual drives
  • Identified and shut down running VMs
  • Used OpenSSL to encrypt the virtual hard disk files
  • Deleted logs and replaced reconnaissance files with profanity-laced placeholders
  • Customised file suffixes and embedded encryption keys and attacker contact details

The entire process was completed within three hours, underscoring the speed and precision of modern ransomware groups such as REvil and DarkSide.

 

Why Was Python Used in This Attack?

Python is not typically associated with ransomware, but it’s pre-installed on Linux-based systems like ESXi, making it ideal for these types of attacks. As Andrew Brandt of Sophos notes:

“Python-based ransomware is rare but highly effective on Linux systems. ESXi servers are particularly attractive targets because a single attack can compromise multiple virtual machines running critical applications.”

 

What This Means for Your Business

This incident is a stark reminder that virtual infrastructure is just as vulnerable as traditional endpoints. Businesses using ESXi or any virtualised environment must ensure:

  • The ESXi Shell is disabled when not in use
  • Remote access tools like TeamViewer are properly secured with MFA and activity monitoring
  • Virtual machine backups are encrypted and stored separately
  • Ransomware detection tools are in place and regularly updated
  • SSH and remote access logs are monitored for unusual activity

 

Protect Your Business from Ransomware

At IT Pro Tech, we help Australian businesses harden their IT environments against the latest ransomware threats. Whether you’re using VMware, Hyper-V, or cloud-based infrastructure, we provide:

  • Ransomware prevention and recovery solutions
  • Endpoint and VM security audits
  • 24/7 threat monitoring and response
  • Employee training and incident response planning

📞 Call us now on 02 9387 3888

Don’t wait until it’s too late. Let us help you secure your virtual infrastructure from evolving ransomware threats.

Call Back

Book A Call Back

Preferred Call Time
:
MM slash DD slash YYYY

This will close in 0 seconds

Have A Question ?

Call Back

Get In Touch

Your Name(Required)

This will close in 0 seconds

This content is private. Please log in to view it.

This will close in 0 seconds

This content is private. Please log in to view it.

This will close in 0 seconds

Managed - Have A Question ?

Get In Touch

Your Name(Required)

This will close in 0 seconds

GeeksforGeeks logo

Book A Call Back

Preferred Call Time
:
MM slash DD slash YYYY

This will close in 0 seconds

This will close in 0 seconds