ESET reported that the KillDisk malware expanded from Windows to Linux systems, targeting Linux machines with a fake ransomware scheme that demanded $250,000 in exchange for recovery. The malware encrypted filenames and damaged data on infected hosts, displaying a ransom note that claimed victims could regain access after payment.
Researchers found the Linux variant lacked any practical mechanism to restore files, indicating the operation functioned as a destructive wiper rather than true ransomware. The finding reinforced concerns that attackers were using ransomware-style extortion as cover for sabotage, leaving affected organizations with little recovery path beyond backups and system rebuilds.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
ESET published research describing a Linux variant of KillDisk that demanded a $250,000 ransom but lacked any capability to restore encrypted files, indicating the payment demand was not a functional decryption scheme. The report marked a new development in KillDisk activity by documenting Linux targeting.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.