cheers
INACTIVEransomware group
Cheers is a Linux-based ransomware variant observed starting in May 2022, engineered specifically to target VMware ESXi servers. The malware was developed from leaked Babuk ransomware source code and leverages the SOSEMANUK stream cipher combined with ECDH key exchange for encryption. It terminates all running virtual machines before renaming and encrypting log files and VM-related extensions—like .vmdk, .vmsn, and .vswp—appending a .Cheers extension. A ransom note titled "How To Restore Your Files.txt" is dropped per directory. The ransomware is attributed to the Chinese-affiliated group BRONZE STARLIGHT (also known as Emperor Dragonfly, DEV-0401), which has previously deployed other strains like Rook, NightSky, and Pandora. Cheers targets a range of industry sectors, with confirmed victims across healthcare, finance, logistics, and manufacturing.
Group Activity
Last 12 monthsVictims (14)
DYNAM JAPAN HOLDINGS CO., LTD
An Japan Game Halls Operator
An British Financial Company -Public
An Insurance Company -Paid
An Turkey Certified Public Accountancy Firms -Unpay
An Insurance Company
An British Financial Company -Unpay
An International Shipping Company - Paid
An International Shipping Company - Unpay
Sembcorp Marine - Unpay
An Technology Company - Paid
An Financial Company - Paid
An Belgium Hospital - Unpay
An International Maritime Company - Unpay
Infrastructure
unreachable
http://rwiajgajdr4kzlnrj5zwebbukpcbrjhupjmk6gufxv6tg7myx34iocad.onion4333ms
11d ago
unreachable
http://crkfkmrh4qzbddfrl2axnkvjp5tgwx73d7lq4oycsfxc7pfgbfhtfiid.onion/4239ms
11d ago