Skip to content
← LibraryTechnique entry
HV-ESXI-RANSOMImpact

ESXi Mass-Encrypt Ransomware

Once root on ESXi, enumerate /vmfs/volumes and encrypt every .vmdk in place — single host outage takes down hundreds of VMs.

§ Where this technique fits

HV-ESXI-RANSOM is catalogued under the Impact tactic of the offensive-security kill-chain. It appears in 3 approved dossiers in the registry, typically at step 5.7 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 1×
  2. 02seen 1×