GoGoogle is a ransomware operation known to have developed a Linux encryptor for attacks against VMware ESXi environments. It is part of the broader shift among enterprise-focused ransomware groups toward Linux-based tooling designed to maximize impact in virtualized infrastructure, where compromising a single hypervisor can disrupt many hosted systems at once. Available reporting supports GoGoogle’s use of a Linux encryptor specifically associated with ESXi targeting, but provides limited public technical detail on the family’s internal functionality, encryption workflow, or broader tradecraft compared with better-documented ransomware families. Based on the available facts, GoGoogle should be understood as an ESXi-targeting ransomware threat within the wave of Linux ransomware development aimed at enterprise virtualization platforms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation mentioned as having created a Linux encryptor.
Referenced as another ransomware operation that created a Linux encryptor targeting ESXi environments.
Ransomware family mentioned as having created a Linux encryptor to target ESXi virtual machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.