Security researchers have sounded the alarm over a dramatic rise in ransomware attacks targeting hypervisors, with incidents increasing by more than 700 percent in the second half of the year.
Analysts at Huntress reported that hypervisors — the underlying systems that run and manage virtual machines — accounted for just three percent of malicious encryption cases in the first half of the year. That figure has since jumped to 25 percent, marking what they describe as a major and worrying shift in cyber-criminal tactics.
The surge is being driven primarily by the Akira ransomware group, which, along with other attackers, is increasingly going after hypervisors to bypass traditional endpoint and network defences. By compromising the host system, criminals can manipulate entire virtual environments and dramatically amplify the impact of their intrusion.
Huntress researchers warned that hypervisors often lack the full range of security tools available on standard operating systems, creating blind spots similar to those exploited in past attacks on VPN appliances. Because defenders cannot easily install Endpoint Detection and Response tools on proprietary or restricted hypervisor platforms, attackers are finding them easier to breach.
The threat hunters say they have witnessed multiple cases where ransomware is deployed directly through the hypervisor, completely sidestepping endpoint protections. In some instances, attackers have used built-in tools such as OpenSSL to encrypt virtual machine volumes, avoiding the need to introduce custom ransomware binaries. They have also observed misuse of Hyper-V management utilities to alter VM settings, disable security features, tamper with virtual switches and prepare large-scale ransomware deployments.
Attackers are also breaking into networks, stealing authentication credentials and then targeting hypervisors as a second stage of attack.
Given the escalation, Huntress recommends administrators revisit security fundamentals such as enforcing multi-factor authentication, using complex passwords and ensuring systems are fully patched. They also advise implementing hypervisor-specific safeguards, such as allow-listing approved binaries and ensuring security monitoring systems ingest hypervisor logs.
Cyber-security experts have long warned that hypervisors represent a high-value target. A successful “VM escape” — where an attacker breaks out of a virtual machine and gains control of the host — would be catastrophic, particularly for hyperscale cloud providers who rely on virtualisation to isolate customer workloads.
The latest findings underscore how strongly attackers are now focusing on the core infrastructure that underpins modern computing, and how vital it is for organisations to shore up defences before the trend accelerates further.