A threat actor operating under the handle EclipseSupport is actively promoting a new Ransomware-as-a-Service (RaaS) operation named Eclipse Ransomware on cybercrime forums.
The group is recruiting cybercrime affiliates, claiming its platform can compromise a wide spectrum of enterprise systems, including Windows, Linux servers, NAS storage appliances, VMware ESXi hypervisors, and Nutanix virtualized infrastructure.
Unlike traditional single-OS malware, Eclipse Ransomware is engineered from the ground up as a multi-platform deployment.
The Windows payload is written in Rust, leveraging the language’s memory-safety, performance, and evasion characteristics, while the variants targeting Linux, NAS devices, ESXi, and Nutanix environments are developed in C++.
This dual-codebase approach allows the operators to effectively target hybrid enterprise environments, virtualized cloud workloads, and on-premises data centers.
The emergence of cross-platform encryptors mirrors a growing industry trend seen across other RaaS platform models designed to maximize impact across diverse server fleets.
Eclipse Ransomware Launches RaaS Platform
The malware operators claim that Eclipse Ransomware utilizes ChaCha20 symmetric encryption paired with Kyber-based post-quantum cryptographic key exchange mechanisms.
Affiliates are offered configurable encryption modes to balance operational speed against stealth, helping ensure file locking finishes before local security tools respond.
As spotted by DarkWebInformer, the platform includes specific routines designed to encrypt Hyper-V virtual machines and disable Veeam backup infrastructure.
Neutralizing backup repositories and hypervisor stores is a high-value tactic intended to prevent organizations from performing clean system restores.
For Windows domain environments, the platform allegedly embeds automated features for:
- Automated Lateral Movement: Propagating across active Active Directory domains.
- Defense Evasion: Disabling endpoint security agents and endpoint detection tools.
- Process Termination: Killing database services, backup agents, and open file handles prior to encryption.
Targeting hypervisors allows threat actors to execute high-impact VMware ESXi attacks, crippling hundreds of virtual servers simultaneously.
Eclipse Ransomware operates as a fully managed affiliate ecosystem. The administrative web panel provides centralized campaign controls, multi-user team access, automated payment validation, real-time activity logging, and an integrated LiveChat portal to handle victim ransom negotiations directly.
| Management Feature | Technical Implementation |
| Payment Options | Separate Bitcoin (BTC) and Monero (XMR) wallets per target |
| Anonymity Layer | Dedicated Tor .onion negotiation addresses generated for each victim |
| Data Extortion | Direct leak-site publishing options embedded in the affiliate panel |
| Future Modules | Automated cloud/tape backup targeting, data exfiltration, and FreeBSD/OpenBSD builds |
The developers leverage double extortion tactics, threatening to publish stolen corporate data on dedicated leak sites if victims refuse to pay the decryption ransom.
To attract experienced affiliates, EclipseSupport is offering an introductory 90/10 revenue split in favor of the affiliate for their first 10 successful extortion cases, after which the split adjusts to a standard 80/20 ratio.
Applicants are required to pay a $300 entry fee—which the operators claim is fully refundable upon the affiliate’s first successful ransom payout—and must target organizations with an expected payout threshold of at least $70,000.
Affiliates are strictly forbidden from submitting ransomware samples to VirusTotal or public multi-scanner portals.
While the claims made by EclipseSupport have not been independently verified in wild intrusions, security teams should proactively harden enterprise networks:
- Protect Virtualization Layers: Isolate ESXi and Hyper-V management interfaces behind strict network segmentation and require multi-factor authentication (MFA).
- Harden Backup Systems: Ensure Veeam and enterprise backup servers use immutable storage, out-of-band credentials, and isolated network paths.
- Audit Active Directory: Enforce least-privilege policies to block unauthorized lateral movement and script execution across Windows domains.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now
Click Here For The Original Source.
