As detailed in Bleeping Computer, ransomware operators are increasingly abusing virtual machines (VMs) provisioned by ISPsystem, a legitimate virtual infrastructure management provider, to host and distribute malicious payloads at scale.Cybersecurity researchers at Sophos observed this tactic during investigations into recent ransomware incidents, noting the attackers' use of Windows VMs with identical hostnames. These hostnames appear to be default templates generated by ISPsystem's VMmanager. This method is exploited by bulletproof hosting providers, allowing malicious actors to create command-and-control (C2) and payload-delivery infrastructure that is difficult to distinguish from legitimate systems.This evasion technique complicates attribution and hinders swift takedowns. Multiple ransomware groups, including LockBit, Qilin, and Conti, along with infostealer campaigns, have been linked to this abuse. A small cluster of disreputable hosting providers, such as Stark Industries Solutions Ltd. and Zomro B.V., are predominantly hosting these malicious VMs.Source: Bleeping Computer
Ransomware, Threat Intelligence
Ransomware operators exploit ISPsystem VM templates for malicious infrastructure

An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



