A new Ransomware-as-a-Service (RaaS) initiative, named Eclipse Ransomware, is being promoted by a cybercriminal group known as EclipseSupport. This operation is being advertised on cybercrime forums, targeting various enterprise systems, including Windows, Linux servers, NAS storage appliances, VMware ESXi hypervisors, and Nutanix virtualized infrastructure.
Multi-Platform Targeting
Eclipse Ransomware is uniquely designed to operate across multiple platforms. Its Windows variant is developed using Rust, chosen for its memory safety and performance, while the versions aimed at Linux, NAS, ESXi, and Nutanix are built with C++. This dual-codebase strategy enables the ransomware to effectively attack hybrid enterprise environments, as well as both cloud-based and on-premises data centers. This trend in cross-platform ransomware reflects a broader movement within the RaaS landscape to enhance impact on varied server infrastructures.
Advanced Encryption Techniques
The ransomware employs ChaCha20 symmetric encryption along with Kyber-based post-quantum cryptographic key exchange mechanisms. Affiliates can configure encryption settings to optimize between speed and stealth, ensuring that file encryption is completed before any security tools can react. As identified by DarkWebInformer, the ransomware includes features to encrypt Hyper-V virtual machines and disable Veeam backup systems, a tactic aimed at obstructing clean system restorations.
The platform is equipped with automated tools to facilitate lateral movement across Active Directory domains, disable endpoint security, and terminate processes that could interfere with encryption. This capability allows the ransomware to execute high-impact attacks on VMware ESXi, affecting numerous virtual servers simultaneously.
Affiliate Ecosystem and Revenue Model
Eclipse Ransomware functions within a managed affiliate network, offering a centralized web panel for campaign management, payment handling, and direct negotiation with victims. The system supports Bitcoin and Monero for ransom payments, and employs Tor for anonymous communication. Affiliates are incentivized with a 90/10 revenue split for their initial ten successful extortions, transitioning to an 80/20 split thereafter. An initial entry fee of $300 is required, refundable upon the first successful ransom payment, with a minimum target payout threshold of $70,000.
Security experts advise enterprises to strengthen their defenses against such threats. Recommendations include isolating virtualization management interfaces with strict network segmentation and employing multi-factor authentication, securing backup systems with immutable storage and isolated network paths, and enforcing least-privilege policies within Active Directory to prevent unauthorized access and script execution.
While the full extent of EclipseSupport’s claims remains unverified, organizations are urged to proactively enhance their cybersecurity measures to counter potential threats from this emerging ransomware operation.
