Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Obsidian boss says there are no plans for The Outer Worlds 3 following missed targets for the 2025 sequel

    Ares Interactive’s “AI-enabled development, marketing, and live-ops” secures $70m in Series A Funding

    Take-Two pauses development on Borderlands 4 Switch 2 port

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      Arthur Hayes Attributes Bitcoin Crash to ETF-Linked Dealer Hedging

      February 8, 2026

      Monero XMR Attempts First Recovery in a Month, But Death Cross Risk Looms

      February 8, 2026

      HBAR Price Eyes a Potential 30% Rally – Here’s What the Charts are Signalling 

      February 8, 2026

      Bitcoin Mining Difficulty Hits Its Biggest Drop Since 2021 China Ban

      February 8, 2026

      How Severe Is This Bitcoin Bear Market and Where Is Price Headed Next?

      February 8, 2026
    • Technology

      How to stream the 2026 Super Bowl for free tonight: Patriots vs. Seahawks time, where to watch Super Bowl LX, start time, halftime show and more

      February 8, 2026

      AT&T’s budget-friendly phone for kids was designed with parental controls in mind

      February 8, 2026

      We may see Apple’s new iPads and MacBooks in only a matter of weeks

      February 8, 2026

      Steam now lets developers display the exact date of when their game leaves Early Access

      February 8, 2026

      The iPhone 17e will reportedly bring some key upgrades without raising the price

      February 8, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Ransomware gang uses ISPsystem VMs for stealthy payload delivery
    Technology

    Ransomware gang uses ISPsystem VMs for stealthy payload delivery

    TechAiVerseBy TechAiVerseFebruary 8, 2026No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Ransomware gang uses ISPsystem VMs for stealthy payload delivery
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Ransomware gang uses ISPsystem VMs for stealthy payload delivery

    Ransomware operators are hosting and delivering malicious payloads at scale by abusing virtual machines (VMs) provisioned by ISPsystem, a legitimate virtual infrastructure management provider.

    Researchers at cybersecurity company Sophos observed the tactic while investigating recent ‘WantToCry’ ransomware incidents. They found the attackers used Windows VMs with identical hostnames, suggesting default templates generated by ISPsystem’s VMmanager.

    Diving deeper, the researchers discovered that the same hostnames were present in the infrastructure of multiple ransomware operators, including LockBit, Qilin, Conti, BlackCat/ALPHV, and Ursnif, as well as various malware campaigns involving RedLine and Lummar info-stealers.

    Location of devices using the same hostname
    Source: Sophos

    ISPsystem is a legitimate software company that develops control panels for hosting providers, used for the management of virtual servers, OS maintenance, etc. VMmanager is the company’s virtualization management platform used to spin up Windows or Linux VMs for customers.

    Sophos found that VMmanager’s default Windows templates reuse the same hostname and system identifiers every time they are deployed.

    Bulletproof hosting providers that knowingly support cybercrime operations and ignore takedown requests take advantage of this design weakness. They allow malicious actors to spin up VMs via VMmanager, used for command-and-control (C2) and payload-delivery infrastructure.

    This essentially hides malicious systems among thousands of innocuous ones, complicates attribution, and makes quick takedowns unlikely.

    The majority of the malicious VMs were hosted by a small cluster of providers with a bad reputation or sanctions, including Stark Industries Solutions Ltd., Zomro B.V., First Server Limited, Partner Hosting LTD, and JSC IOT.

    Sophos has also discovered a provider with direct control of physical infrastructure named MasterRDP, which uses VMmanager for evasion and offers VPS and RDP services that do not comply with legal requests.

    According to Sophos, four of the most prevalent ISPsystem hotnames “account for over 95% of the total number of internet-facing ISPsystem virtual machines:”

    • WIN-LIVFRVQFMKO
    • WIN-LIVFRVQFMKO
    • WIN-344VU98D3RU
    • WIN-J9D866ESIJ2

    All of them were present either in customer detection or telemetry data linked to cybercriminal activity.

    The researchers note that while ISPsystem VMmanager is a legitimate platform for virtualization management, it is also attractive to cybercriminals due to “its low cost, low barrier to entry, and turnkey deployment capabilities.”

    BleepingComputer has contacted ISPsystem to ask if they are aware of the large-scale abuse of VM templates and their plans to address the issue, but a statement wasn’t available by publishing time.

    Update 2/6 – A spokesperson of ISPsystem sent BleepingComputer the following statement, which confirms they have added randomization in hostname assignment:

    “We thank Sophos CTU for their research. As the developers of VMmanager, we understand that the very qualities that make our platform effective for business—simplicity and speed of deployment—can be misused. We have already released an update for the Windows templates: now, each time a new virtual machine is deployed, its name is generated randomly. This eliminates the possibility of technical identifier overlap and addresses the specific risk highlighted in the report. We value the experts’ contribution to security and are ready to help build a secure environment together.” – ISPsystem team


    The future of IT infrastructure is here

    Modern IT infrastructure moves faster than manual workflows can handle.

    In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleMicrosoft to shut down Exchange Online EWS in April 2027
    Next Article Spain’s Ministry of Science shuts down systems after breach claims
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    How to stream the 2026 Super Bowl for free tonight: Patriots vs. Seahawks time, where to watch Super Bowl LX, start time, halftime show and more

    February 8, 2026

    AT&T’s budget-friendly phone for kids was designed with parental controls in mind

    February 8, 2026

    We may see Apple’s new iPads and MacBooks in only a matter of weeks

    February 8, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025659 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025246 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025148 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Gaming February 8, 2026

    Obsidian boss says there are no plans for The Outer Worlds 3 following missed targets for the 2025 sequel

    Obsidian boss says there are no plans for The Outer Worlds 3 following missed targets…

    Ares Interactive’s “AI-enabled development, marketing, and live-ops” secures $70m in Series A Funding

    Take-Two pauses development on Borderlands 4 Switch 2 port

    NBA 2K and Grand Theft Auto franchises boost Take-Two Q3 net revenue by 25% to $1.7bn

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Obsidian boss says there are no plans for The Outer Worlds 3 following missed targets for the 2025 sequel

    February 8, 20260 Views

    Ares Interactive’s “AI-enabled development, marketing, and live-ops” secures $70m in Series A Funding

    February 8, 20260 Views

    Take-Two pauses development on Borderlands 4 Switch 2 port

    February 8, 20260 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.