Linux RATs on Windows: Ransomware Actors Target VMware Deployments
## Agenda Ransomware Group's Cross-Platform Attack Strategy
Agenda Ransomware Group's Cross-Platform Attack Strategy
The Agenda ransomware group has introduced an advanced attack technique by deploying Linux ransomware variants directly on Windows systems. This development poses a significant challenge to conventional endpoint security measures.
The attack utilizes WinSCP for secure file transfer to move Linux ransomware binaries onto Windows machines. The ransomware is then executed using Splashtop Remote management software, allowing it to operate on Windows systems.
Trend Micro Research identified this campaign, which targets VMware infrastructure and backup systems. It combines legitimate remote management tools with bring-your-own-vulnerable-driver (BYOVD) techniques to evade detection and encrypt hybrid enterprise environments.
The approach bypasses many endpoint detection systems that are primarily configured to monitor native Windows executables rather than Linux binaries executed through remote management channels.
Systematic Targeting of Backup Infrastructure
The campaign specifically targets Veeam backup systems, compromising disaster recovery capabilities before deploying ransomware. Attackers executed PowerShell scripts with base64-encoded payloads to extract and decrypt stored credentials from multiple Veeam backup databases.
The Agenda ransomware group has introduced an advanced attack technique by deploying Linux ransomware variants directly on Windows systems.
These databases contained authentication credentials for domain controllers, Exchange servers, SQL databases, and file servers across enterprise infrastructures. By compromising these systems, the Agenda group gained extensive access to remote systems while also impairing the organization's recovery ability.
Global Impact and Victimology Patterns
Agenda has emerged as a significant ransomware-as-a-service operation in 2025, affecting victims in the United States, Western Europe, and Japan. The group targets high-value sectors such as manufacturing, technology, financial services, and healthcare. This pattern indicates a focus on industries with operational sensitivity and a higher likelihood of ransom payment.
The attack method challenges traditional security architectures focused on Windows systems. Executing Linux binaries through legitimate remote management tools on Windows platforms represents a notable security blind spot.
Organizations should reassess their security posture to address hybrid environment threats and cross-platform ransomware techniques. Security teams must enhance monitoring of remote management tools, restrict RMM platforms to authorized hosts, and enforce multifactor authentication on administrative access. Critical backup infrastructure should be segmented from production networks, with strict enforcement of least privilege on credential access. Detection rules should be updated to identify unsigned driver loads, DLL sideloading attempts, and Linux binary execution on Windows systems through remote administration tools.
The Agenda ransomware campaign highlights the rapid adaptation of threat actors. The combination of BYOVD techniques, legitimate tool abuse, backup infrastructure targeting, and cross-platform execution methods creates a complex attack vector requiring comprehensive visibility across hybrid environments to effectively detect and prevent attacks.
Based on reporting by GBHackers.
