Attackers used a custom Python ransomware script to encrypt virtual disks on a VMware ESXi hypervisor, taking the victim organization’s virtual machines offline after gaining access through a TeamViewer account that lacked multi-factor authentication on a system used by a Domain Administrator. Sophos said the intrusion moved from initial access to ransomware deployment in just over three hours, with the attackers scanning the network using Advanced IP Scanner and reaching the ESXi server through Bitvise after finding ESXi Shell enabled.
The script, fcker.py, was copied to the hypervisor and executed against multiple datastores, where it shut down VMs, encrypted datastore files with OpenSSL using per-file AES material, overwrote the originals, and tried to remove evidence. Sophos identified the malware as Troj/Ransom-GJR and reported that it generated unique key pairs for each datastore run, leaving encrypted private keys on disk because it had no built-in exfiltration capability; the company urged organizations to harden ESXi, disable ESXi Shell when not required, and enforce MFA on privileged remote-access accounts.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Sophos Rapid Response recovered a copy of the Python ransomware despite the attackers' attempts to overwrite and delete it. The analysis found the malware used OpenSSL-based per-file encryption, generated unique key pairs per datastore execution, and left encrypted private keys on disk because it lacked exfiltration capability.
Roughly three hours after the network scan, the attackers copied a Python script named fcker.py to the ESXi datastore and executed it once per targeted datastore. The script shut down virtual machines and encrypted files on three datastores, taking the victim's VMs offline.
Just before 2 a.m., the attackers downloaded the Bitvise SSH client and used it to access the VMware ESXi server. They were able to do so because ESXi Shell had been enabled previously and not disabled afterward.
About ten minutes after gaining access, the attackers downloaded and ran Advanced IP Scanner to identify targets on the victim network. The scan helped them locate the VMware ESXi server later used in the attack.
Sophos said the ransomware intrusion began when attackers logged into a TeamViewer account without multi-factor authentication on a computer used by a Domain Administrator. This initial access started the attack sequence that later reached the ESXi hypervisor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.