VYPR
breachPublished Aug 12, 2026· 1 source

Eclipse Ransomware Launches Multi-Platform RaaS Targeting Windows, Linux, and Virtualized Infrastructure

A new Ransomware-as-a-Service (RaaS) platform named Eclipse Ransomware has emerged, developed in Rust and C++ to target a wide array of enterprise systems including Windows, Linux, ESXi, and Nutanix.

A new Ransomware-as-a-Service (RaaS) operation, dubbed Eclipse Ransomware, is actively being promoted on cybercrime forums by a threat actor operating under the alias EclipseSupport. This new platform aims to recruit affiliates by offering a sophisticated toolset capable of compromising diverse enterprise environments. Unlike many RaaS offerings that focus on a single operating system, Eclipse Ransomware boasts a multi-platform approach, with its Windows payload written in Rust for performance and evasion, and variants for Linux, NAS devices, VMware ESXi, and Nutanix developed in C++. This dual-codebase strategy allows for effective targeting of hybrid cloud and on-premises data center infrastructures.

The malware employs ChaCha20 symmetric encryption, augmented by Kyber-based post-quantum cryptographic key exchange mechanisms. Affiliates can configure encryption modes to balance speed and stealth, aiming to complete file encryption before defensive measures can be deployed. Notably, the platform includes specific routines designed to target and disable backup infrastructure, such as Veeam, and encrypt virtual machines hosted on hypervisors like VMware ESXi. This tactic is intended to cripple an organization's ability to recover from an attack by preventing clean system restores.

For Windows environments, the Eclipse Ransomware platform allegedly includes automated features for lateral movement across Active Directory domains, defense evasion by disabling endpoint security tools, and process termination to halt critical services and backup agents before encryption commences. The ability to target hypervisors allows attackers to potentially impact hundreds of virtual servers simultaneously, maximizing disruption.

Eclipse Ransomware operates as a fully managed affiliate program. The administrative panel provides centralized campaign management, multi-user access, automated payment processing, real-time activity logging, and an integrated chat portal for direct negotiation with victims. The platform also offers features for data extortion, including options to publish stolen corporate data on dedicated leak sites if ransom demands are not met, employing a double extortion strategy.

To attract affiliates, EclipseSupport is offering an attractive initial revenue split of 90% for the affiliate on their first ten successful operations, before reverting to a 80/20 split. Applicants are required to pay a $300 entry fee, which is reportedly refundable upon the first successful ransom payout, and must commit to targeting organizations with an expected ransom value of at least $70,000. Strict rules are in place for affiliates, including a prohibition against submitting ransomware samples to public scanners like VirusTotal.

While the full capabilities and in-the-wild deployment of Eclipse Ransomware have yet to be independently verified, security professionals are advised to proactively enhance their defenses. This includes isolating virtualization management interfaces, implementing strict network segmentation, requiring multi-factor authentication for critical systems, and ensuring backup systems utilize immutable storage and isolated network paths. Auditing Active Directory for least-privilege policies is also crucial to prevent unauthorized lateral movement.

The emergence of Eclipse Ransomware highlights a continuing trend of sophisticated, multi-platform RaaS operations designed to maximize impact across diverse IT infrastructures. The use of modern programming languages like Rust and advanced cryptographic techniques, combined with a focus on disabling backups and targeting virtualized environments, presents a significant challenge for defenders.

Synthesized by Vypr AI