Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Adobe ColdFusion flaws let attackers run arbitrary code
August 12, 2026
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
Home/CyberSecurity News/Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
CyberSecurity News

Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi

Key Takeaways A new Ransomware-as-a-Service (RaaS) called Eclipse Ransomware has emerged, actively recruiting affiliates on underground forums. The platform is designed for multi-platform attacks,...

Marcus Rodriguez
Marcus Rodriguez
August 12, 2026 3 Min Read
2 0

Key Takeaways

  • A new Ransomware-as-a-Service (RaaS) called Eclipse Ransomware has emerged, actively recruiting affiliates on underground forums.
  • The platform is designed for multi-platform attacks, targeting Windows, Linux servers, NAS devices, VMware ESXi, and Nutanix virtualized environments.
  • Eclipse Ransomware leverages a dual-codebase (Rust for Windows, C++ for others) and features advanced capabilities like Hyper-V VM encryption and Veeam backup disruption.
  • Operators employ double extortion tactics and offer an attractive revenue split to affiliates, requiring a $300 entry fee and a minimum $70,000 target payout.

A new Ransomware-as-a-Service (RaaS) operation, dubbed Eclipse Ransomware, is currently being promoted on cybercrime forums by a threat actor operating under the alias EclipseSupport. This new venture aims to recruit affiliates for widespread attacks against diverse enterprise systems.

Table Of Content

  • Key Takeaways
  • Technical Specifications and Attack Capabilities
  • RaaS Ecosystem and Affiliate Program
  • What You Should Do

The group claims its platform can compromise a broad array of organizational infrastructure, encompassing Windows and Linux servers, Network Attached Storage (NAS) appliances, VMware ESXi hypervisors, and Nutanix virtualized environments.

Eclipse Ransomware distinguishes itself by adopting a multi-platform design from its inception, moving beyond the limitations of single-operating-system malware. This strategic development reflects a growing trend among sophisticated RaaS models to maximize impact across varied IT infrastructures.

Technical Specifications and Attack Capabilities

The Windows payload for Eclipse Ransomware is engineered in Rust, a programming language valued for its memory safety, performance, and resistance to common evasion techniques. Conversely, the variants designed for Linux, NAS devices, ESXi, and Nutanix environments are developed using C++. This dual-codebase strategy enables the operators to effectively target hybrid enterprise setups, virtualized cloud workloads, and on-premises data centers with a unified RaaS offering.

The malware operators assert that Eclipse Ransomware employs ChaCha20 symmetric encryption, combined with Kyber-based post-quantum cryptographic key exchange mechanisms for robust security. Affiliates are provided with customizable encryption modes, allowing them to balance the speed of execution against stealth, ensuring that file encryption completes before local security tools can intervene.

As observed by DarkWebInformer, the platform incorporates specific routines to encrypt Hyper-V virtual machines and disable Veeam backup infrastructure. These tactics are considered high-value targets, as neutralizing backup repositories and hypervisor stores is a critical step in preventing organizations from performing clean system restores and forcing ransom payments.

For Windows domain environments, the platform reportedly includes automated features designed for:

  • Automated Lateral Movement: Facilitating propagation across Active Directory domains.
  • Defense Evasion: Disabling endpoint security agents and detection tools.
  • Process Termination: Shutting down database services, backup agents, and open file handles before initiating encryption.

The capability to target hypervisors allows threat actors to launch high-impact VMware ESXi attacks, potentially crippling hundreds of virtual servers simultaneously within an organization.

RaaS Ecosystem and Affiliate Program

Eclipse Ransomware operates as a comprehensive, managed affiliate ecosystem. The administrative web panel offers centralized campaign controls, multi-user team access, automated payment validation, real-time activity logging, and an integrated LiveChat portal for direct victim ransom negotiations.

The developers employ double extortion tactics, threatening to publish stolen corporate data on dedicated leak sites if victims refuse to pay the demanded decryption ransom. The platform’s management features are extensive:

  • Payment Options: Separate Bitcoin (BTC) and Monero (XMR) wallets are generated for each target.
  • Anonymity Layer: Dedicated Tor .onion negotiation addresses are created for every victim.
  • Data Extortion: Direct leak-site publishing options are integrated into the affiliate panel.
  • Future Modules: Planned features include automated cloud/tape backup targeting, data exfiltration, and builds for FreeBSD/OpenBSD.

To attract seasoned cybercriminals, EclipseSupport is offering an introductory 90/10 revenue split in favor of the affiliate for their initial 10 successful extortion cases. Following this, the split adjusts to a standard 80/20 ratio. Prospective affiliates must pay a $300 entry fee, which the operators claim is fully refundable upon the affiliate’s first successful ransom payout. Additionally, affiliates are required to target organizations with an expected payout threshold of at least $70,000 and are strictly prohibited from submitting ransomware samples to public multi-scanner portals like VirusTotal.

While the claims made by EclipseSupport regarding successful intrusions remain unverified, security teams are strongly advised to proactively strengthen their enterprise networks against such threats.

What You Should Do

  • Protect Virtualization Layers: Implement strict network segmentation for ESXi and Hyper-V management interfaces and enforce multi-factor authentication (MFA).
  • Harden Backup Systems: Ensure Veeam and other enterprise backup solutions utilize immutable storage, out-of-band credentials, and isolated network paths.
  • Audit Active Directory: Enforce least-privilege policies to prevent unauthorized lateral movement and script execution across Windows domains.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareransomwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

WhatsApp launches new scam alert feature to combat social engineering

Next Post

Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
2.86 Billion Credentials Compromised, Enterprise Access for Sale
August 12, 2026
Fake Chrome VPN Extensions Hijack Traffic via SOCKS5 Proxies
August 12, 2026
WindRelay Malware Uses SpyNote RAT, NFC Relay to Drain Accounts
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us