GoGoogle is a ransomware operation publicly noted as one of several enterprise-focused groups that developed a Linux encryptor to target VMware ESXi and other Linux-based server environments. Its inclusion alongside groups such as REvil, Babuk, RansomExx/Defray, Mespinoza, DarkSide, and HelloKitty places it within the broader trend of ransomware actors expanding beyond Windows to maximize impact against virtualized infrastructure. High-confidence reporting supports that GoGoogle possessed Linux ransomware capability, specifically in the context of ESXi-focused attacks, but the available information does not establish further details about its origin, victimology, operational structure, aliases beyond the canonical name, or distinctive tradecraft. Based on the confirmed facts, GoGoogle should be characterized as a financially motivated ransomware threat actor with Linux/ESXi encryption capability.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a ransomware group that created a Linux encryptor.
Mentioned as another ransomware operation that created Linux encryptors targeting ESXi environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.