Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Aurora ransomware affiliate's privilege-escalation/lateral-movement playbook included “EternalBlue (MS17-010).” | Deux variantes de l’encrypteur Aurora ont été identifiées, toutes deux écrites en Zig : Windows (sap.exe) et Linux/ESXi (encrypt.out).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers identified a Linux variant of Aurora ransomware, an ELF binary manually copied to several internal hosts. It includes an -esxi mode that terminates virtual-machine processes before encrypting virtual-machine files.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Le variant Linux/ESXi chiffre les contenus des fichiers en place avec ChaCha20; il cible notamment les fichiers de machines virtuelles VMware.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware encryptor with Windows and Linux/ESXi variants compiled from a shared Zig codebase. The Windows variant deletes VSS snapshots, disables System Restore, and checks for Hyper-V; the Linux/ESXi variant forcibly stops virtual machines before encryption and injects a ransom note into the ESXi SSH banner. The affiliate exfiltrated data before encryption and conducted victim-specific ransom negotiations.
Linux/ESXi-targeting ransomware active since approximately April 2026. It encrypts files in place using ChaCha20, protects the session key with an embedded RSA-4096 public key, kills ESXi VM processes to release virtual-disk locks, targets VMware VM files, avoids BOOTBANK and OSDATA system volumes to preserve hypervisor availability, writes an SSH ransom banner, and drops the ransom note !!!README!!!DO_NOT_DELETE.txt. A second attributed cluster reportedly used SQL Server xp_cmdshell for lateral movement, GodPotato for SYSTEM elevation, DCSync, and s5cmd-based S3-compatible storage exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.