A cybercriminal gang known as EclipseSupport is promoting a new Ransomware-as-a-Service (RaaS) operation called Eclipse Ransomware on forums This article explores eclipse ransomware designed. . They are recruiting affiliates and claim their platform can compromise various enterprise systems including Windows, Linux servers, NAS storage appliances, VMware ESXi hypervisors, and Nutanix virtualized infrastructures.

Unlike traditional single-platform malware, the Eclipse Ransomware is designed to be multi-platform, with a Windows payload written in Rust for enhanced memory safety, performance, and evasion capabilities. Eclipse Ransomware, spearheaded by malware operators, employs ChaCha20 symmetric encryption combined with Kyber-based post-quantum cryptographic key exchange mechanisms. The administrative web panel offers comprehensive campaign management, multi-user team access, automated payment validation, real-time activity logging, and an integrated LiveChat portal for direct victim negotiation handling.

Management Features Technical Implementation Payment Options: Separate Bitcoin (BTC) and Monero (XMR) wallets per target Anonymity Layer: Dedicated Tor .onion negotiation addresses generated for each victim Data Extortion: Direct leak-site publishing options embedded in the affiliate panel Future Modules: Automated cloud/tape backup targeting, data exfiltration, and FreeBSD/OpenBSD builds The developers employ double extortion tactics, threatening to publish stolen corporate data on dedicated leak sites if victims refuse to pay the decryption ransom. While EclipseSupport’s claims remain unverified in real-world incidents, cybersecurity professionals should proactively fortify enterprise networks: Isolate ESXi and Hyper-V management interfaces behind strict network segmentation and require multi-factor authentication (MFA).