Eclipse Ransomware RaaS Targets Windows, Linux, ESXi

Eclipse RaaS claims multi‑platform targeting of Windows, Linux, ESXi and backups

Eclipse Ransomware RaaS has entered the cybercrime marketplace, targeting Windows, Linux, and ESXi infrastructure. This emerging platform, while not yet linked to confirmed attacks, signals a notable evolution in ransomware tooling and affiliate models.

Details of the Eclipse Ransomware RaaS Offering

On 12 August 2026, a threat actor using the alias EclipseSupport began advertising the Eclipse Ransomware-as-a-Service (RaaS) on cybercrime forums. The service is marketed as a cross-platform solution capable of targeting complex enterprise environments. According to the forum post, Eclipse Ransomware offers tailored payloads for:

  • Windows domain environments
  • Linux servers
  • VMware ESXi hypervisors
  • Microsoft Hyper V virtual machines
  • NAS appliances
  • Nutanix virtualised infrastructure
  • Veeam backup platforms (for targeted disablement)

Technical claims from the actor specify that the Windows locker is written in Rust, whereas variants for Linux, NAS, ESXi, and Nutanix are developed in C++. This dual-language approach is designed to ensure effective compromise in mixed-OS and virtualised enterprise settings.

The ransomware’s cryptographic routines reportedly use ChaCha20 for file encryption, with Kyber-based post-quantum key exchange protecting session keys. The use of Kyber in ransomware, while still rare, aligns with the trend of adopting newer cryptographic schemes to counter evolving security tools.

Platform Capabilities and Affiliate Model

The forum advert describes a suite of features aimed at maximising operational impact and affiliate appeal. Key elements include:

  • Automated lateral movement across Active Directory domains
  • Defence evasion, including disabling endpoint security agents
  • Termination of database services, backup agents, and open file handles before encryption
  • Targeted encryption of Hyper V virtual machines
  • Specific routines to disable Veeam backup infrastructure

The affiliate control panel is said to provide granular campaign management, unique cryptocurrency wallets (Bitcoin and Monero) per victim, Tor-based negotiation addresses, direct leak-site publishing, and a LiveChat channel for ransom negotiation. The business model offers a 90/10 revenue split for the first 10 cases, dropping to 80/20 thereafter, with a $300 entry fee (refundable after the first payout) and a $70,000 minimum target threshold. Notably, affiliates are explicitly banned from submitting samples to VirusTotal, likely to evade early detection or analysis.

Future modules are promised, including automation for cloud and tape backup targeting, data exfiltration features, and support for FreeBSD/OpenBSD systems, further expanding the platform’s reach.

Timeline and Exploitation Status

The first public reporting of the Eclipse RaaS platform appeared on 12 August 2026. As of this date, there have been no confirmed victim disclosures, and Eclipse does not appear on ransomware leak site aggregators such as Ransomware.live or RansomLook. No mainstream malware repositories or security advisories include samples or technical indicators relating to Eclipse. The only known actor is EclipseSupport, with no external attribution or proof-of-concept samples identified.

This lack of corroborated incidents means that, at present, Eclipse Ransomware remains a watch item rather than a verified threat. However, the sophistication of the claimed features and the focus on disabling recovery infrastructure are consistent with trends in recent high-value ransomware campaigns.

Technical Features and Claimed Enterprise Impact

The Eclipse Ransomware advert focuses on maximising disruption in enterprise and hybrid cloud environments. Standout technical claims include:

  • Cross-platform encryptors (Rust for Windows, C++ for others)
  • ChaCha20 encryption with Kyber key exchange
  • Automated lateral movement in Active Directory domains
  • Automated disabling of endpoint detection and response (EDR) tools
  • Pre-encryption termination of critical business and backup processes
  • Encryption of virtual machines and disabling of backup systems to hinder recovery

This approach is designed to undermine common enterprise defences, particularly backup and virtualisation layers. The focus on Veeam and hypervisors like VMware ESXi and Hyper V directly targets the backbone of many organisations’ business continuity plans.

Why Eclipse Ransomware Matters

While Eclipse Ransomware has not yet been observed in real-world attacks, its design and the affiliate model reflect a growing shift towards cross-platform, enterprise-targeting ransomware. For UK organisations, particularly SMBs using virtualisation and Veeam, the platform’s stated capabilities are relevant to common infrastructure setups. Even without confirmed exploitation, the emergence of such tooling underscores the importance of hardening backup and virtualisation systems.

Recommended Actions for Organisations

  • Review and implement immutability and separation controls for backup repositories, following Veeam and UK NCSC guidance.
  • Apply hardening and network segmentation for hypervisors (VMware ESXi, Hyper V) as per vendor security baselines.
  • Monitor for suspicious lateral movement and unauthorised process termination in Active Directory and virtualised environments.

No indicators of compromise have been published. Organisations should remain alert for future updates and advisories as more information emerges.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call