Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Ransomware gang uses ISPsystem VMs for stealthy payload delivery
    Cybersecurity

    Ransomware gang uses ISPsystem VMs for stealthy payload delivery

    adminBy adminFebruary 6, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Ransomware gang uses ISPsystem VMs for stealthy payload delivery
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ransomware gang uses ISPsystem VMs for stealthy payload delivery

    Ransomware operators are hosting and delivering malicious payloads at scale by abusing virtual machines (VMs) provisioned by ISPsystem, a legitimate virtual infrastructure management provider.

    Researchers at cybersecurity company Sophos observed the tactic while investigating recent ‘WantToCry’ ransomware incidents. They found the attackers used Windows VMs with identical hostnames, suggesting default templates generated by ISPsystem’s VMmanager.

    Diving deeper, the researchers discovered that the same hostnames were present in the infrastructure of multiple ransomware operators, including LockBit, Qilin, Conti, BlackCat/ALPHV, and Ursnif, as well as various malware campaigns involving RedLine and Lummar info-stealers.

    Wiz
    Location of devices using the same hostname
    Location of devices using the same hostname
    Source: Sophos

    ISPsystem is a legitimate software company that develops control panels for hosting providers, used for the management of virtual servers, OS maintenance, etc. VMmanager is the company’s virtualization management platform used to spin up Windows or Linux VMs for customers.

    Sophos found that VMmanager’s default Windows templates reuse the same hostname and system identifiers every time they are deployed.

    Bulletproof hosting providers that knowingly support cybercrime operations and ignore takedown requests take advantage of this design weakness. They allow malicious actors to spin up VMs via VMmanager, used for command-and-control (C2) and payload-delivery infrastructure.

    This essentially hides malicious systems among thousands of innocuous ones, complicates attribution, and makes quick takedowns unlikely.

    The majority of the malicious VMs were hosted by a small cluster of providers with a bad reputation or sanctions, including Stark Industries Solutions Ltd., Zomro B.V., First Server Limited, Partner Hosting LTD, and JSC IOT.

    Sophos has also discovered a provider with direct control of physical infrastructure named MasterRDP, which uses VMmanager for evasion and offers VPS and RDP services that do not comply with legal requests.

    According to Sophos, four of the most prevalent ISPsystem hotnames “account for over 95% of the total number of internet-facing ISPsystem virtual machines:”

    • WIN-LIVFRVQFMKO
    • WIN-LIVFRVQFMKO
    • WIN-344VU98D3RU
    • WIN-J9D866ESIJ2

    All of them were present either in customer detection or telemetry data linked to cybercriminal activity.

    The researchers note that while ISPsystem VMmanager is a legitimate platform for virtualization management, it is also attractive to cybercriminals due to “its low cost, low barrier to entry, and turnkey deployment capabilities.”

    BleepingComputer has contacted ISPsystem to ask if they are aware of the large-scale abuse of VM templates and their plans to address the issue, but a statement wasn’t available by publishing time.


    tines

    Modern IT infrastructure moves faster than manual workflows can handle.

    In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

    delivery gang ISPsystem payload ransomware stealthy VMs
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleTransform your monitor into a smart TV for just $16
    Next Article Google Ads no longer runs on keywords. It runs on intent.
    admin
    • Website

    Related Posts

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026

    Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Boost Mobile Review – No-Contract 5G Plans Starting at $25/Month

    June 4, 2026

    Google Confirms LLMs.txt Has No Current Implementation

    June 4, 2026

    Will Broadcom’s VMware strategy keep paying big dividends?

    June 4, 2026

    How Google Display exclusions guide AI-driven optimization

    June 4, 2026
    Categories
    • Blogging (89)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (235)
    • SEO & Digital Marketing (1,365)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (331)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Boost Mobile Review – No-Contract 5G Plans Starting at $25/Month

    June 4, 2026

    Google Confirms LLMs.txt Has No Current Implementation

    June 4, 2026

    Will Broadcom’s VMware strategy keep paying big dividends?

    June 4, 2026
    Most Popular
    • Boost Mobile Review – No-Contract 5G Plans Starting at $25/Month
    • Google Confirms LLMs.txt Has No Current Implementation
    • Will Broadcom’s VMware strategy keep paying big dividends?
    • How Google Display exclusions guide AI-driven optimization
    • How to show in search, social, and AI
    • 9 Best Cheap Cell Phone Plans That Will Save You Money
    • How To Fix Google Ads Smart Bidding With A Primary vs. Secondary Conversion Framework
    • What is Cisco Cloud Control and why should customers care?
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.