Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems

Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems

Posted on August 12, 2026 By CWS

A new Ransomware-as-a-Service (RaaS) initiative, named Eclipse Ransomware, is being promoted by a cybercriminal group known as EclipseSupport. This operation is being advertised on cybercrime forums, targeting various enterprise systems, including Windows, Linux servers, NAS storage appliances, VMware ESXi hypervisors, and Nutanix virtualized infrastructure.

Multi-Platform Targeting

Eclipse Ransomware is uniquely designed to operate across multiple platforms. Its Windows variant is developed using Rust, chosen for its memory safety and performance, while the versions aimed at Linux, NAS, ESXi, and Nutanix are built with C++. This dual-codebase strategy enables the ransomware to effectively attack hybrid enterprise environments, as well as both cloud-based and on-premises data centers. This trend in cross-platform ransomware reflects a broader movement within the RaaS landscape to enhance impact on varied server infrastructures.

Advanced Encryption Techniques

The ransomware employs ChaCha20 symmetric encryption along with Kyber-based post-quantum cryptographic key exchange mechanisms. Affiliates can configure encryption settings to optimize between speed and stealth, ensuring that file encryption is completed before any security tools can react. As identified by DarkWebInformer, the ransomware includes features to encrypt Hyper-V virtual machines and disable Veeam backup systems, a tactic aimed at obstructing clean system restorations.

The platform is equipped with automated tools to facilitate lateral movement across Active Directory domains, disable endpoint security, and terminate processes that could interfere with encryption. This capability allows the ransomware to execute high-impact attacks on VMware ESXi, affecting numerous virtual servers simultaneously.

Affiliate Ecosystem and Revenue Model

Eclipse Ransomware functions within a managed affiliate network, offering a centralized web panel for campaign management, payment handling, and direct negotiation with victims. The system supports Bitcoin and Monero for ransom payments, and employs Tor for anonymous communication. Affiliates are incentivized with a 90/10 revenue split for their initial ten successful extortions, transitioning to an 80/20 split thereafter. An initial entry fee of $300 is required, refundable upon the first successful ransom payment, with a minimum target payout threshold of $70,000.

Security experts advise enterprises to strengthen their defenses against such threats. Recommendations include isolating virtualization management interfaces with strict network segmentation and employing multi-factor authentication, securing backup systems with immutable storage and isolated network paths, and enforcing least-privilege policies within Active Directory to prevent unauthorized access and script execution.

While the full extent of EclipseSupport’s claims remains unverified, organizations are urged to proactively enhance their cybersecurity measures to counter potential threats from this emerging ransomware operation.

Cyber Security News Tags:Affiliates, backup protection, Cybercrime, Cybersecurity, DarkWebInformer, data extortion, Eclipse Ransomware, Encryption, ESXi, Linux, network security, RaaS, Threat Actors, Virtualization, Windows

Post navigation

Previous Post: Mindgard Secures $30 Million to Enhance AI Security

Related Posts

NVIDIA GPU Display Driver Vulnerabilities Allows Code Execution and Privilege Escalation NVIDIA GPU Display Driver Vulnerabilities Allows Code Execution and Privilege Escalation Cyber Security News
Critical Hikvision Vulnerability Threatens Wireless Access Points Critical Hikvision Vulnerability Threatens Wireless Access Points Cyber Security News
Microsoft Domain Faces Trust Issues Due to Expired Certificate Microsoft Domain Faces Trust Issues Due to Expired Certificate Cyber Security News
Critical SharePoint Flaw Allows Remote Code Execution Critical SharePoint Flaw Allows Remote Code Execution Cyber Security News
Critical SQL Injection Flaw in Microsoft Manager Alerted by CISA Critical SQL Injection Flaw in Microsoft Manager Alerted by CISA Cyber Security News
Microsoft Intune MDM and Entra ID Leveraged to Elevate your Trust in Device Identity Microsoft Intune MDM and Entra ID Leveraged to Elevate your Trust in Device Identity Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update
  • WhatsApp Introduces Scam Alert to Enhance User Safety

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems
  • Mindgard Secures $30 Million to Enhance AI Security
  • Global Cyber Campaign Targets Salesforce and ServiceNow
  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update
  • WhatsApp Introduces Scam Alert to Enhance User Safety

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark