Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Linux RATs on Windows: Ransomware Actors Target VMware Deployments

## Agenda Ransomware Group's Cross-Platform Attack Strategy

Agenda Ransomware Group's Cross-Platform Attack Strategy

The Agenda ransomware group has introduced an advanced attack technique by deploying Linux ransomware variants directly on Windows systems. This development poses a significant challenge to conventional endpoint security measures.

The attack utilizes WinSCP for secure file transfer to move Linux ransomware binaries onto Windows machines. The ransomware is then executed using Splashtop Remote management software, allowing it to operate on Windows systems.

Trend Micro Research identified this campaign, which targets VMware infrastructure and backup systems. It combines legitimate remote management tools with bring-your-own-vulnerable-driver (BYOVD) techniques to evade detection and encrypt hybrid enterprise environments.

The approach bypasses many endpoint detection systems that are primarily configured to monitor native Windows executables rather than Linux binaries executed through remote management channels.

Systematic Targeting of Backup Infrastructure

The campaign specifically targets Veeam backup systems, compromising disaster recovery capabilities before deploying ransomware. Attackers executed PowerShell scripts with base64-encoded payloads to extract and decrypt stored credentials from multiple Veeam backup databases.

The Agenda ransomware group has introduced an advanced attack technique by deploying Linux ransomware variants directly on Windows systems.
Rebecca Stone · Thehackingpost

These databases contained authentication credentials for domain controllers, Exchange servers, SQL databases, and file servers across enterprise infrastructures. By compromising these systems, the Agenda group gained extensive access to remote systems while also impairing the organization's recovery ability.

Global Impact and Victimology Patterns

Agenda has emerged as a significant ransomware-as-a-service operation in 2025, affecting victims in the United States, Western Europe, and Japan. The group targets high-value sectors such as manufacturing, technology, financial services, and healthcare. This pattern indicates a focus on industries with operational sensitivity and a higher likelihood of ransom payment.

The attack method challenges traditional security architectures focused on Windows systems. Executing Linux binaries through legitimate remote management tools on Windows platforms represents a notable security blind spot.

Advertisement

Organizations should reassess their security posture to address hybrid environment threats and cross-platform ransomware techniques. Security teams must enhance monitoring of remote management tools, restrict RMM platforms to authorized hosts, and enforce multifactor authentication on administrative access. Critical backup infrastructure should be segmented from production networks, with strict enforcement of least privilege on credential access. Detection rules should be updated to identify unsigned driver loads, DLL sideloading attempts, and Linux binary execution on Windows systems through remote administration tools.

The Agenda ransomware campaign highlights the rapid adaptation of threat actors. The combination of BYOVD techniques, legitimate tool abuse, backup infrastructure targeting, and cross-platform execution methods creates a complex attack vector requiring comprehensive visibility across hybrid environments to effectively detect and prevent attacks.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories