Kraken Cross-Platform Ransomware Attacking Windows, Linux, and VMware ESXi Systems in Enterprise Environments

Kraken Cross-Platform Ransomware Attacking Windows, Linux, and VMware ESXi Systems in Enterprise Environments

In August 2025, a new ransomware threat emerged with capabilities that fundamentally changed how organizations should approach enterprise security.

Kraken, a Russian-speaking cybercriminal group, began executing sophisticated attacks targeting large organizations across multiple continents.

What makes Kraken particularly dangerous is its ability to attack Windows, Linux, and VMware ESXi systems with platform-specific tools, making it one of the first truly cross-platform ransomware threats to gain widespread notoriety in enterprise circles.

The Kraken group appears to be connected to the HelloKitty ransomware operation, with security researchers suspecting the group emerged from the remnants of that previous criminal organization.

Kraken data leak blog (Source - Cisco Talos)
Kraken data leak blog (Source – Cisco Talos)

This connection becomes evident through shared ransom note filenames and explicit references on the group’s leak site.

Kraken ransom note (Source - Cisco Talos)
Kraken ransom note (Source – Cisco…