Cheerscrypt is a malicious software (malware) that was discovered in May 2022, specifically designed to target ESXi servers, which are extensively used by enterprises for server virtualization. This discovery was made following the reporting of DarkSide ransomware variants in May 2021. Cheerscrypt, like other malware, can infiltrate systems through suspicious downloads, emails, or websites, and once inside, it can disrupt operations, steal personal data, or even hold your data hostage for ransom.
The analysis suggests that Cheerscrypt and another malware called ESXi Args are likely based on leaked Babuk source code, which has been previously used in other ESXi ransomware campaigns, including Quantum/Dagon group’s PrideLocker encryptor. Interestingly, the ransom notes from Cheerscrypt and ESXi Args, circulated between October 2022 and February 2023, share striking similarities in their wording. However, differences in encryption methods have raised questions about whether they represent new variants or just share a common Babuk codebase.
Cheerscrypt gained notoriety in early 2022 and is part of an alarming trend of ransomware attacks targeting ESXi servers. Other recent examples include ESXiArgs and Luna. These attacks underscore the escalating threat landscape for enterprise server infrastructure and highlight the need for robust cybersecurity measures to protect against such threats.
Description last updated: 2024-07-22T15:16:41.427Z