Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
Play Ransomware Group's New Linux Variant Targets ESXi, Shows Ties With Prolific Puma
Trend AI Research Blog Jul 2024

Play Ransomware Group's New Linux Variant Targets ESXi, Shows Ties With Prolific Puma

RansomwareCross-PlatformDefense Evasion

Trend AI threat hunters discovered the first Linux variant of Play ransomware specifically targeting ESXi environments. The analysis revealed infrastructure connections to Prolific Puma, a threat actor known for providing link-shortening services to cybercriminals. The ESXi variant shares code similarities with the Windows version but includes ESXi-specific routines for VM management and datastore encryption. This discovery demonstrates the continued trend of major ransomware groups developing dedicated Linux/ESXi payloads to maximize impact on enterprise virtualization infrastructure.