RansomHouse, a ransomware-as-a-service (RaaS) operation, has introduced a new tool called 'MrAgent' aimed at automating the deployment of its data encrypter across multiple VMware ESXi hypervisors. This tool is specifically designed to target ESXi systems, which are often utilized by large organizations to deploy virtual computers hosting valuable data and critical applications. By compromising these ESXi servers, RansomHouse maximizes the impact of its ransomware attacks, potentially disrupting essential business operations. MrAgent is capable of identifying host systems, disabling firewalls, and automating the ransomware deployment process across multiple hypervisors simultaneously. It supports custom configurations received from the command and control (C2) server, allowing for various parameters to be set, such as passwords, encryption commands, scheduling events, and modifying welcome messages to display ransom notices. Additionally, MrAgent can execute local commands on the hypervisor, delete files, drop active SSH sessions, and provide information about running virtual machines. The tool's ability to disable firewalls and drop SSH sessions reduces the likelihood of detection and intervention by administrators while targeting all reachable virtual machines at once, thereby increasing the attack's impact. Trellix researchers have identified both Windows and Linux versions of MrAgent, indicating the attackers' intent to extend its applicability across different platforms and maximize campaign effectiveness. Trellix emphasizes the significance of these automation efforts, underscoring the attacker's interest in targeting large networks. Given the severe security implications posed by tools like MrAgent, defenders must implement robust security measures, including regular updates, strong access controls, network monitoring, and logging, to effectively defend against such threats.
Microsoft has disclosed details of a cryptocurrency-focused malware campaign targeting Windows users since February 2026. The operation centers on clipper malware, a threat designe...
A critical security vulnerability identified as CVE-2023-6875 has been discovered in the widely used POST as in the POST SMTP Mailer plugin versions up to 2.8.7 and is caused by an...
A critical security flaw identified as CVE-2026-20266 has been disclosed by Splunk, affecting its AI Toolkit component. The weakness impacts versions earlier than 5.7.4 and could a...