Ransomware, Threat Intelligence

Ransomware operators exploit ISPsystem VM templates for malicious infrastructure

As detailed in Bleeping Computer, ransomware operators are increasingly abusing virtual machines (VMs) provisioned by ISPsystem, a legitimate virtual infrastructure management provider, to host and distribute malicious payloads at scale.

Cybersecurity researchers at Sophos observed this tactic during investigations into recent ransomware incidents, noting the attackers' use of Windows VMs with identical hostnames. These hostnames appear to be default templates generated by ISPsystem's VMmanager. This method is exploited by bulletproof hosting providers, allowing malicious actors to create command-and-control (C2) and payload-delivery infrastructure that is difficult to distinguish from legitimate systems.

This evasion technique complicates attribution and hinders swift takedowns. Multiple ransomware groups, including LockBit, Qilin, and Conti, along with infostealer campaigns, have been linked to this abuse. A small cluster of disreputable hosting providers, such as Stark Industries Solutions Ltd. and Zomro B.V., are predominantly hosting these malicious VMs.

Source: Bleeping Computer

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds