Kyber changes the usual ransomware problem. It does not just encrypt a server or a few endpoints. It can hit VMware ESXi and Windows file servers in the same environment, and its anti-recovery measures make guest restores and host recovery fail together, which can turn a contained incident into a full operational blackout.
Rapid7’s March 2026 incident response found two Kyber payloads deployed side by side in one environment, one for ESXi and one for Windows Server. The ESXi variant targets datastore encryption and can terminate virtual machines or deface management interfaces. The Windows variant is written in Rust, and both samples share a campaign identifier and Tor-based ransom infrastructure, showing coordinated cross-platform deployment.
The risk is not just data loss. When the hypervisor layer and the file-server layer are both encrypted, normal recovery paths can disappear at the same time, and outage duration becomes the attacker’s leverage.
Kyber ransomware gang toys with post-quantum encryption on Windows
A new Kyber ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with one variant implementing Kyber1024 post-quantum encryption.
Kyber Ransomware Double Trouble: Windows and ESXi Attacks Explained
Organizations should treat Kyber not merely as another ransomware strain, but as a specialized tool capable of causing a complete operational blackout.