Eclipse Ransomware Unveils Multi-Platform RaaS Targeting Enterprise Systems

A new Ransomware-as-a-Service (RaaS) operation, known as Eclipse Ransomware, has been introduced by a threat actor using the alias EclipseSupport. This platform is being actively promoted on cybercrime forums, with the group seeking affiliates to deploy attacks across a broad range of enterprise systems, including Windows, Linux servers, NAS storage devices, VMware ESXi hypervisors, and Nutanix virtualized infrastructures.

Unlike traditional ransomware that typically targets a single operating system, Eclipse Ransomware is designed from the outset for multi-platform deployment. The Windows variant is developed in Rust, a programming language recognized for its memory safety and performance benefits. In contrast, the versions targeting Linux, NAS devices, ESXi, and Nutanix environments are written in C++. This dual-codebase strategy enables the ransomware to effectively infiltrate hybrid enterprise environments, encompassing both virtualized cloud workloads and on-premises data centers.

The adoption of cross-platform encryptors reflects a broader trend in the cybercriminal landscape, where RaaS platforms are evolving to maximize their impact across diverse server infrastructures.

Technical Capabilities and Encryption Methods

Eclipse Ransomware reportedly employs ChaCha20 symmetric encryption in conjunction with Kyber-based post-quantum cryptographic key exchange mechanisms. Affiliates have the option to configure encryption modes to balance operational speed with stealth, aiming to complete file encryption before security tools can respond.

Notably, the platform includes specific routines designed to encrypt Hyper-V virtual machines and disable Veeam backup infrastructure. By neutralizing backup repositories and hypervisor stores, the ransomware seeks to prevent organizations from restoring systems from clean backups.

For Windows domain environments, Eclipse Ransomware is said to incorporate automated features for:

  • Automated lateral movement across Active Directory domains.
  • Defense evasion by disabling endpoint security agents and detection tools.
  • Process termination of database services, backup agents, and open file handles prior to encryption.

Targeting hypervisors allows the ransomware to execute high-impact attacks on VMware ESXi systems, potentially crippling numerous virtual servers simultaneously.

Affiliate Program and Operational Structure

Eclipse Ransomware operates as a fully managed affiliate ecosystem. Its administrative web panel offers centralized campaign controls, multi-user team access, automated payment validation, real-time activity logging, and an integrated LiveChat portal for direct victim ransom negotiations.

Key management features include:

  • Separate Bitcoin (BTC) and Monero (XMR) wallets for each target.
  • Dedicated Tor `.onion` negotiation addresses generated for each victim.
  • Direct leak-site publishing options embedded in the affiliate panel.
  • Future modules planned for automated cloud/tape backup targeting, data exfiltration, and FreeBSD/OpenBSD builds.

The developers employ double extortion tactics, threatening to publish stolen corporate data on dedicated leak sites if victims refuse to pay the ransom.

To attract experienced affiliates, EclipseSupport offers an initial 90/10 revenue split in favor of the affiliate for their first ten successful extortion cases, after which the split adjusts to a standard 80/20 ratio. Prospective affiliates are required to pay a $300 entry fee, which is refundable upon the affiliate’s first successful ransom payout. Additionally, affiliates must target organizations with an expected payout threshold of at least $70,000 and are strictly prohibited from submitting ransomware samples to public multi-scanner portals like VirusTotal.

While the claims made by EclipseSupport have not been independently verified in real-world intrusions, security teams are advised to proactively strengthen enterprise networks by:

  1. Protecting virtualization layers by isolating ESXi and Hyper-V management interfaces behind strict network segmentation and requiring multi-factor authentication (MFA).
  2. Hardening backup systems by ensuring Veeam and enterprise backup servers use immutable storage, out-of-band credentials, and isolated network paths.
  3. Auditing Active Directory configurations to identify and remediate potential vulnerabilities that could facilitate lateral movement.

The emergence of Eclipse Ransomware underscores the increasing sophistication and adaptability of RaaS platforms. By targeting a wide array of enterprise systems and offering a comprehensive affiliate program, this operation exemplifies the evolving threat landscape. Organizations must remain vigilant and implement robust security measures to defend against such multifaceted ransomware threats.