Researchers Warn Of 700 Percent Surge In Hypervisor Ransomware

Security researchers have sounded the alarm over a dramatic rise in ransomware attacks targeting hypervisors, with incidents increasing by…
cybersecurity - securitybuyer.com

Share this article:

Security researchers have sounded the alarm over a dramatic rise in ransomware attacks targeting hypervisors, with incidents increasing by more than 700 percent in the second half of the year.

Analysts at Huntress reported that hypervisors — the underlying systems that run and manage virtual machines — accounted for just three percent of malicious encryption cases in the first half of the year. That figure has since jumped to 25 percent, marking what they describe as a major and worrying shift in cyber-criminal tactics.

The surge is being driven primarily by the Akira ransomware group, which, along with other attackers, is increasingly going after hypervisors to bypass traditional endpoint and network defences. By compromising the host system, criminals can manipulate entire virtual environments and dramatically amplify the impact of their intrusion.

Huntress researchers warned that hypervisors often lack the full range of security tools available on standard operating systems, creating blind spots similar to those exploited in past attacks on VPN appliances. Because defenders cannot easily install Endpoint Detection and Response tools on proprietary or restricted hypervisor platforms, attackers are finding them easier to breach.

The threat hunters say they have witnessed multiple cases where ransomware is deployed directly through the hypervisor, completely sidestepping endpoint protections. In some instances, attackers have used built-in tools such as OpenSSL to encrypt virtual machine volumes, avoiding the need to introduce custom ransomware binaries. They have also observed misuse of Hyper-V management utilities to alter VM settings, disable security features, tamper with virtual switches and prepare large-scale ransomware deployments.

Attackers are also breaking into networks, stealing authentication credentials and then targeting hypervisors as a second stage of attack.

Given the escalation, Huntress recommends administrators revisit security fundamentals such as enforcing multi-factor authentication, using complex passwords and ensuring systems are fully patched. They also advise implementing hypervisor-specific safeguards, such as allow-listing approved binaries and ensuring security monitoring systems ingest hypervisor logs.

Cyber-security experts have long warned that hypervisors represent a high-value target. A successful “VM escape” — where an attacker breaks out of a virtual machine and gains control of the host — would be catastrophic, particularly for hyperscale cloud providers who rely on virtualisation to isolate customer workloads.

The latest findings underscore how strongly attackers are now focusing on the core infrastructure that underpins modern computing, and how vital it is for organisations to shore up defences before the trend accelerates further.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Scroll to Top