Kyber Turns ESXi and Windows Into One Blackout

Kyber changes the usual ransomware problem. It does not just encrypt a server or a few endpoints. It can hit VMware ESXi and Windows file servers in the same environment, and its anti-recovery measures make guest restores and host recovery fail together, which can turn a contained incident into a full operational blackout. Rapid7’s March 2026 incident response found two Kyber payloads deployed side by side in one environment, one for ESXi and one for Windows Server. The ESXi variant targets datastore encryption and can terminate virtual machines or deface management interfaces. The Windows variant is written in Rust, and both samples share a campaign identifier and Tor-based ransom infrastructure, showing coordinated cross-platform deployment. The risk is not just data loss. When the hypervisor layer and the file-server layer are both encrypted, normal recovery paths can disappear at the same time, and outage duration becomes the attacker’s leverage.

Part of the PlainSec briefing for 2026-04-22

Sources