Sophos researchers investigating late-2025 WantToCry ransomware incidents found repeated use of Windows virtual machines provisioned through ISPsystem VMmanager, where default images assigned static, autogenerated hostnames that were not randomized during deployment. Those identifiers appeared across thousands of internet-exposed RDP systems, heavily concentrated in Russia and nearby regions, and surfaced in operations tied to multiple malware and ransomware families including LockBit, Qilin, BlackCat/ALPHV, Conti, TrickBot, Ursnif, and NetSupport RAT.
The report says the pattern does not prove a single shared operator, because unrelated actors can inherit the same hostnames and artifacts simply by using the same VM template. Sophos also found many of the exposed systems clustered at hosting providers including Stark Industries Solutions Ltd and First Server Limited, both previously linked in public reporting and sanctions to Russian state-connected or criminal activity, alongside underground advertising for bulletproof hosting and leased RDP access. Researchers concluded that ISPsystem VMmanager is legitimate software, but its low-cost, turnkey deployment model and common default configurations have made it attractive infrastructure for ransomware, malware delivery, phishing, botnet management, and data staging.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Sophos publicly released its report concluding that ISPsystem VMmanager is legitimate software but that its low-cost, turnkey deployment model and widespread use make it attractive to threat actors while also blending in with legitimate deployments.
The researchers found concentrations of these systems at providers including Stark Industries Solutions Ltd and First Server Limited and identified underground advertising for bulletproof hosting and RDP services tied to the same ISPsystem-derived infrastructure.
Sophos confirmed that ISPsystem VMmanager default Windows images contain fixed hostnames and related identifiers that are not randomized during provisioning, which can make unrelated threat actors appear to share infrastructure.
During the investigation, Sophos found that these template-derived hostnames appeared on thousands of internet-exposed RDP systems, especially in Russia and nearby regions, and were seen across operations involving LockBit, Qilin, BlackCat/ALPHV, Conti, TrickBot, Ursnif, NetSupport RAT, and other malware campaigns.
In late 2025, Sophos Counter Threat Unit investigated WantToCry ransomware cases and observed repeated use of Windows virtual machines with static autogenerated hostnames derived from ISPsystem VMmanager templates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.