WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Ransomware Awareness – Abyss Locker Joins Ransomware Trend of Adding Capabilities Targeting VMware ESXi
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Ransomware Awareness – Abyss Locker Joins Ransomware Trend of Adding Capabilities Targeting VMware ESXi

Author: April Zupan

Created: Tuesday, August 1, 2023 - 17:16

Categories: Cybersecurity

Dark Reading has written an article discussing Abyss Locker’s recent addition of the capability to target VMware’s ESXi virtualized environments for encryption, increasing risks for ICS owners and operators.

Abyss Locker was first observed in March of this year as part of double extortion campaigns but, according to the article, version 2 of the ransomware was discovered this month with this new capability. The group has already claimed 14 victims and joined Akira, Black Basta, Cl0p, HelloKitty, IceFire, Hive, LockBit, MichaelKors, Royal, and Revil ransomware groups in moving to Linux to encrypt ESXi machines. It is likely that more ransomware groups will join this trend, likely jumpstarted by the release of Babuk’s source code. Members are encouraged to assess the risk to their virtual environments accordingly. Read more at Dark Reading.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar