The attack, one of the fastest recorded by Sophos researchers, was achieved by operators who “precisiontargeted the ESXi platform” in order to encrypt the virtual machines of the victim.
A new variant written in Python, was deployed ten minutes after threat actors managed to break into a TeamViewer account belonging to the victim organization.