Cybersecurity NewsArchived Aug 12, 2026✓ Full text saved
A threat actor operating under the handle EclipseSupport is actively promoting a new Ransomware-as-a-Service (RaaS) operation named Eclipse Ransomware on cybercrime forums. The group is recruiting cybercrime affiliates, claiming its platform can compromise a wide spectrum of enterprise systems, including Windows, Linux servers, NAS storage appliances, VMware ESXi hypervisors, and Nutanix virtualized infrastructure. Unlike traditional […] The post Eclipse Ransomware Launches RaaS Platform Targeti
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Attack News
Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure
By Guru Baran
August 12, 2026
Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure
A threat actor operating under the handle EclipseSupport is actively promoting a new Ransomware-as-a-Service (RaaS) operation named Eclipse Ransomware on cybercrime forums.
The group is recruiting cybercrime affiliates, claiming its platform can compromise a wide spectrum of enterprise systems, including Windows, Linux servers, NAS storage appliances, VMware ESXi hypervisors, and Nutanix virtualized infrastructure.
Unlike traditional single-OS malware, Eclipse Ransomware is engineered from the ground up as a multi-platform deployment.
The Windows payload is written in Rust, leveraging the language’s memory-safety, performance, and evasion characteristics, while the variants targeting Linux, NAS devices, ESXi, and Nutanix environments are developed in C++.
This dual-codebase approach allows the operators to effectively target hybrid enterprise environments, virtualized cloud workloads, and on-premises data centers.
The emergence of cross-platform encryptors mirrors a growing industry trend seen across other RaaS platform models designed to maximize impact across diverse server fleets.
Eclipse Ransomware Launches RaaS Platform
The malware operators claim that Eclipse Ransomware utilizes ChaCha20 symmetric encryption paired with Kyber-based post-quantum cryptographic key exchange mechanisms.
Affiliates are offered configurable encryption modes to balance operational speed against stealth, helping ensure file locking finishes before local security tools respond.
As spotted by DarkWebInformer, the platform includes specific routines designed to encrypt Hyper-V virtual machines and disable Veeam backup infrastructure.
Neutralizing backup repositories and hypervisor stores is a high-value tactic intended to prevent organizations from performing clean system restores.
For Windows domain environments, the platform allegedly embeds automated features for:
Automated Lateral Movement: Propagating across active Active Directory domains.
Defense Evasion: Disabling endpoint security agents and endpoint detection tools.
Process Termination: Killing database services, backup agents, and open file handles prior to encryption.
Targeting hypervisors allows threat actors to execute high-impact VMware ESXi attacks, crippling hundreds of virtual servers simultaneously.
Eclipse Ransomware operates as a fully managed affiliate ecosystem. The administrative web panel provides centralized campaign controls, multi-user team access, automated payment validation, real-time activity logging, and an integrated LiveChat portal to handle victim ransom negotiations directly.
Management Feature Technical Implementation
Payment Options Separate Bitcoin (BTC) and Monero (XMR) wallets per target
Anonymity Layer Dedicated Tor .onion negotiation addresses generated for each victim
Data Extortion Direct leak-site publishing options embedded in the affiliate panel
Future Modules Automated cloud/tape backup targeting, data exfiltration, and FreeBSD/OpenBSD builds
The developers leverage double extortion tactics, threatening to publish stolen corporate data on dedicated leak sites if victims refuse to pay the decryption ransom.
To attract experienced affiliates, EclipseSupport is offering an introductory 90/10 revenue split in favor of the affiliate for their first 10 successful extortion cases, after which the split adjusts to a standard 80/20 ratio.
Applicants are required to pay a $300 entry fee—which the operators claim is fully refundable upon the affiliate’s first successful ransom payout—and must target organizations with an expected payout threshold of at least $70,000.
Affiliates are strictly forbidden from submitting ransomware samples to VirusTotal or public multi-scanner portals.
While the claims made by EclipseSupport have not been independently verified in wild intrusions, security teams should proactively harden enterprise networks:
Protect Virtualization Layers: Isolate ESXi and Hyper-V management interfaces behind strict network segmentation and require multi-factor authentication (MFA).
Harden Backup Systems: Ensure Veeam and enterprise backup servers use immutable storage, out-of-band credentials, and isolated network paths.
Audit Active Directory: Enforce least-privilege policies to block unauthorized lateral movement and script execution across Windows domains.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Access
Cyber Security News
737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies
Cyber Security News
2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket
Cyber Security News
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Cyber Security News
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?