Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems

Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Diverse Systems

Posted on August 12, 2026 By CWS

A new Ransomware-as-a-Service (RaaS) initiative, named Eclipse Ransomware, is being promoted by a cybercriminal group known as EclipseSupport. This operation is being advertised on cybercrime forums, targeting various enterprise systems, including Windows, Linux servers, NAS storage appliances, VMware ESXi hypervisors, and Nutanix virtualized infrastructure.

Multi-Platform Targeting

Eclipse Ransomware is uniquely designed to operate across multiple platforms. Its Windows variant is developed using Rust, chosen for its memory safety and performance, while the versions aimed at Linux, NAS, ESXi, and Nutanix are built with C++. This dual-codebase strategy enables the ransomware to effectively attack hybrid enterprise environments, as well as both cloud-based and on-premises data centers. This trend in cross-platform ransomware reflects a broader movement within the RaaS landscape to enhance impact on varied server infrastructures.

Advanced Encryption Techniques

The ransomware employs ChaCha20 symmetric encryption along with Kyber-based post-quantum cryptographic key exchange mechanisms. Affiliates can configure encryption settings to optimize between speed and stealth, ensuring that file encryption is completed before any security tools can react. As identified by DarkWebInformer, the ransomware includes features to encrypt Hyper-V virtual machines and disable Veeam backup systems, a tactic aimed at obstructing clean system restorations.

The platform is equipped with automated tools to facilitate lateral movement across Active Directory domains, disable endpoint security, and terminate processes that could interfere with encryption. This capability allows the ransomware to execute high-impact attacks on VMware ESXi, affecting numerous virtual servers simultaneously.

Affiliate Ecosystem and Revenue Model

Eclipse Ransomware functions within a managed affiliate network, offering a centralized web panel for campaign management, payment handling, and direct negotiation with victims. The system supports Bitcoin and Monero for ransom payments, and employs Tor for anonymous communication. Affiliates are incentivized with a 90/10 revenue split for their initial ten successful extortions, transitioning to an 80/20 split thereafter. An initial entry fee of $300 is required, refundable upon the first successful ransom payment, with a minimum target payout threshold of $70,000.

Security experts advise enterprises to strengthen their defenses against such threats. Recommendations include isolating virtualization management interfaces with strict network segmentation and employing multi-factor authentication, securing backup systems with immutable storage and isolated network paths, and enforcing least-privilege policies within Active Directory to prevent unauthorized access and script execution.

While the full extent of EclipseSupport’s claims remains unverified, organizations are urged to proactively enhance their cybersecurity measures to counter potential threats from this emerging ransomware operation.

Cyber Security News Tags:Affiliates, backup protection, Cybercrime, Cybersecurity, DarkWebInformer, data extortion, Eclipse Ransomware, Encryption, ESXi, Linux, network security, RaaS, Threat Actors, Virtualization, Windows

Post navigation

Previous Post: Mindgard Secures $30 Million to Enhance AI Security
Next Post: Critical VMware vCenter Vulnerability Exploited by Hackers

Related Posts

Hackers Weaponize AWS X-Ray Service to Work as Covert Command & Control Server Hackers Weaponize AWS X-Ray Service to Work as Covert Command & Control Server Cyber Security News
6 Million FTP Servers Still Exposed in 2026, Report Reveals 6 Million FTP Servers Still Exposed in 2026, Report Reveals Cyber Security News
71,000+ WatchGuard Devices Vulnerable to Remote Code Execution Attacks 71,000+ WatchGuard Devices Vulnerable to Remote Code Execution Attacks Cyber Security News
Hackers Weaponizing Calendar Files as a New Attack Vector Bypassing Traditional Email Defenses Hackers Weaponizing Calendar Files as a New Attack Vector Bypassing Traditional Email Defenses Cyber Security News
AI-Powered Zero-Day Exploits Raise Cybersecurity Concerns AI-Powered Zero-Day Exploits Raise Cybersecurity Concerns Cyber Security News
Microsoft Outlook Users Face Crashes When Creating New Emails, Temp Fix Issued Microsoft Outlook Users Face Crashes When Creating New Emails, Temp Fix Issued Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Unpatched Citrix NetScaler Flaws Pose Security Threat
  • Citrix Faces Critical NetScaler RCE Vulnerabilities
  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark