<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="margin:0px;font-size:12pt"><span style="margin:0px;background-color:rgb(255, 255, 255)"><span style="margin:0px;background-color:rgb(255, 255, 255)"><span style="margin:0px;background-color:white"><span style="margin:0px;background-color:white"><span style="margin:0px;background-color:white"><span style="margin:0px;background-color:white"><span style="margin:0px;font-size:14.67px">Hello,</span></span></span><span style="margin:0px;background-color:white"></span><span style="margin:0px;background-color:white"></span></span><span style="margin:0px;background-color:white"></span></span><span style="margin:0px;background-color:rgb(255, 255, 255);display:inline !important"></span></span></span></span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<div style="margin:0px;font-size:12pt">
<div style="margin:0px;background-color:rgb(255, 255, 255)">
<div style="margin:0px;background-color:rgb(255, 255, 255)">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:white">
<div style="margin:0px;font-size:12pt;color:black"><span style="margin:0px;background-color:white"></span>
<div style="margin:0px;background-color:white">
<div style="margin:0px;font-size:14.67px;background-color:white">I hope everyone is doing well!</div>
<div style="margin:0px;font-size:14.67px;background-color:white"><br>
</div>
<div style="margin:0px;font-size:14.67px;background-color:white">Below is the entry for today.</div>
<div style="margin:0px;font-size:14.67px;background-color:white"><br>
</div>
<div style="margin:0px;font-size:14.67px;background-color:white">06/29/2021 - Diary entry #294:<br>
<br>
</div>
<blockquote style="font-size:14.67px;background-color:white;margin-top:0px;margin-bottom:0px">
<div style="margin:0px"></div>
<div style="margin:0px"></div>
Covered in several of our Daily Diaries, Sodinokibi (a.k.a REvil) is a ransomware that operates in the Ransomware-as-a-service business model. Since last year, REvil focused on stealing data before encrypting and publishing in their wall-of-shame "Happy Blog"
 if the ransom is not payed, in a double-extortion model.
<div><br>
</div>
<div>Sodinokibi targets Windows machines, but this week a new variant compiled in ELF64 format was found. An attacker can use this new variant to silently encrypt a directory inside a Linux environment. Curiously this new sample seems to be built to attack
 VMware ESXi servers, as upon receiving a command it stops all virtual machines through the esxcli command-line tool (to avoid data corruption) and encrypts the files stored in /vmmfs/ directory.</div>
<div><br>
</div>
This incident makes Sodinokibi an even more dangerous threat. The capability of running in other platforms not only increases the number of services that can be affected, but enables an attacker to dive more deeply into the network. Also, by targeting ESXi
 machines, this threat can encrypt several servers at once, increasing significantly the potential damage in those environments.
<div style="margin:0px"><br>
</div>
</blockquote>
<span style="margin:0px;font-size:14.67px;background-color:white">Kind Regards,</span></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div style="margin:0px"><span style="margin:0px;font-size:12pt"></span></div>
<br>
</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div></div>
<div></div>
<div></div>
<div></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<table style="font-family:"Times New Roman"; font-size:medium; text-align:start">
<tbody>
<tr>
<td width="180" align="left" style="width:180px">
<table width="120" align="left">
<tbody>
<tr>
<td colspan="3" align="center"><a href="https://www.appgate.com/"><img alt="" width="120" height="30" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/logo@2x.png"></a></td>
</tr>
<tr>
<td colspan="3" align="center"> </td>
</tr>
<tr>
<td width="37%" align="center"><a href="https://www.linkedin.com/company/appgate-security/"><img width="18" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/likedin@2x.png"></a></td>
<td width="28%"><a href="https://twitter.com/AppgateSecurity"><img width="20" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/twitter@2x.png"></a></td>
<td width="35%"><a href="https://www.youtube.com/channel/UC-8GvxcZbm-R3EJNl8jYjiQ"><img width="26" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/youtube@2x.png"></a></td>
</tr>
</tbody>
</table>
<p> </p>
</td>
<td width="350" colspan="2" rowspan="2" style="width:350px">
<p style="font-family:Arial,Helvetica,sans-serif; font-size:13px; color:rgb(12,12,12)">
<strong>Felipe Duarte Domingues</strong><br>
Security Researcher<br>
<strong>Appgate</strong></p>
<p style="font-family:Arial,Helvetica,sans-serif; font-size:13px; color:rgb(12,12,12)">
E:<span> </span><font color="#228ebe"><a href="mailto:felipe.duarte@appgate.com" title="mailto:felipe.duarte@appgate.com">felipe.duarte@appgate.com</a></font><br>
O: <span style="background-color:rgb(255,255,255); display:inline!important">+55 19 98840 2509</span></p>
</td>
</tr>
</tbody>
</table>
<br>
</div>
</div>
</div>
</div>
</body>
</html>