Akira Group Targets Hyper-V and VMware ESXi with Ransomware Exploiting Vulnerabilities

Akira Group Targets Hyper-V and VMware ESXi with Ransomware Exploiting Vulnerabilities

Hypervisors the invisible backbone of modern corporate IT have become the new primary battleground for ransomware groups.

According to new data from Huntress, attacks targeting hypervisors to deploy ransomware have skyrocketed in late 2025.

While hypervisors like VMware ESXi and Microsoft Hyper-V power virtually all enterprise virtual machines (VMs), they often lack the security protections of standard endpoints, making them a “force multiplier” for attackers.

Data from the Huntress Security Operations Center (SOC) reveals a disturbing trend: ransomware incidents involving malicious encryption at the hypervisor layer jumped from just 3% in the first half of 2025 to 25% in the second half of the year.

By compromising the hypervisor layer, attackers bypass traditional endpoint detection and response (EDR) tools installed on guest VMs.

Extract from the Huntress Platform detecting an adversary manipulating Hyper-V.

The primary driver of this surge is the