C
月内に
ランサムウェアグループ「Play」が、VMware ESXi仮想マシンを標的とした攻撃を展開しています
📌 一言でいうと
ランサムウェアグループ「Play」が、VMware ESXi仮想マシンを標的とした攻撃を展開しています。このマルウェアはESXi環境を検出し、仮想マシンを強制停止させた後、仮想ディスクや設定ファイルを暗号化し、拡張子「.PLAY」を付与します。攻撃者はルートディレクトリに身代金要求書を配置し、復旧と引き換えに金銭を要求します。
🔍該当判定
- 社内でサーバー仮想化ソフトの「VMware ESXi」を利用している
- VMware vSphere環境で仮想マシン(VM)を運用している
- サーバーのファイルシステムに「VMFS」を使用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. VMware ESXiおよびvSphereの最新セキュリティパッチを適用すること。 2. 仮想マシンの定期的なオフラインバックアップを確保すること。 3. 不審なプロセスの動作や、仮想マシンの予期せぬ停止を監視すること。 4. 管理者権限へのアクセス制御(MFAの導入など)を強化すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】VMware ESXiを標的としたPlayランサムウェアへの対応について
お疲れさまです。PlayランサムウェアによるVMware ESXiへの攻撃に関する情報共有です。
■ 概要
ランサムウェアグループ「Play」が、VMware ESXi環境を特に対象とした攻撃を行っています。システムを検知すると仮想マシンを強制停止させ、仮想ディスク(VMDK)や設定ファイルを暗号化(拡張子 .PLAY)し、可用性を完全に奪う挙動が確認されています。
■ 影響範囲
- VMware ESXi を搭載した Linux システム
- VMware vSphere の VMFS (Virtual Machine File System) を利用するシステム
■ 対応手順
1. ESXiホストおよびvCenter Serverの最新アップデートを適用し、既知の脆弱性を排除してください。
2. 仮想マシンのバックアップが正常に動作しているか、およびバックアップデータが攻撃者から隔離されているかを確認してください。
3. ESXiへの管理アクセス(SSH, Web UI)を制限し、多要素認証 (MFA) を導入してください。
■ 参考情報
- ThaiCERT 警告通知
対応優先度: 高
対応期限: 速やかに確認
お疲れさまです。PlayランサムウェアによるVMware ESXiへの攻撃に関する情報共有です。
■ 概要
ランサムウェアグループ「Play」が、VMware ESXi環境を特に対象とした攻撃を行っています。システムを検知すると仮想マシンを強制停止させ、仮想ディスク(VMDK)や設定ファイルを暗号化(拡張子 .PLAY)し、可用性を完全に奪う挙動が確認されています。
■ 影響範囲
- VMware ESXi を搭載した Linux システム
- VMware vSphere の VMFS (Virtual Machine File System) を利用するシステム
■ 対応手順
1. ESXiホストおよびvCenter Serverの最新アップデートを適用し、既知の脆弱性を排除してください。
2. 仮想マシンのバックアップが正常に動作しているか、およびバックアップデータが攻撃者から隔離されているかを確認してください。
3. ESXiへの管理アクセス(SSH, Web UI)を制限し、多要素認証 (MFA) を導入してください。
■ 参考情報
- ThaiCERT 警告通知
対応優先度: 高
対応期限: 速やかに確認
Subject: [Security Alert] Play Ransomware Targeting VMware ESXi
Dear IT Administration Team,
We are sharing critical intelligence regarding the Play ransomware group's campaign targeting VMware ESXi environments.
■ Overview
The Play ransomware specifically targets VMware ESXi to maximize impact. Upon infection, it detects the ESXi environment, shuts down all active virtual machines, and encrypts critical files (virtual disks, configuration, and metadata) appending the .PLAY extension.
■ Scope of Impact
- Linux systems running VMware ESXi
- Systems utilizing VMware vSphere's VMFS (Virtual Machine File System)
■ Recommended Actions
1. Ensure all ESXi hosts and vCenter Server instances are updated to the latest patched versions.
2. Verify the integrity and isolation of virtual machine backups (offline/immutable backups).
3. Restrict administrative access to ESXi (SSH, Web UI) and implement Multi-Factor Authentication (MFA).
■ Reference
- ThaiCERT Threat Alert
Priority: High
Deadline: Immediate review
Dear IT Administration Team,
We are sharing critical intelligence regarding the Play ransomware group's campaign targeting VMware ESXi environments.
■ Overview
The Play ransomware specifically targets VMware ESXi to maximize impact. Upon infection, it detects the ESXi environment, shuts down all active virtual machines, and encrypts critical files (virtual disks, configuration, and metadata) appending the .PLAY extension.
■ Scope of Impact
- Linux systems running VMware ESXi
- Systems utilizing VMware vSphere's VMFS (Virtual Machine File System)
■ Recommended Actions
1. Ensure all ESXi hosts and vCenter Server instances are updated to the latest patched versions.
2. Verify the integrity and isolation of virtual machine backups (offline/immutable backups).
3. Restrict administrative access to ESXi (SSH, Web UI) and implement Multi-Factor Authentication (MFA).
■ Reference
- ThaiCERT Threat Alert
Priority: High
Deadline: Immediate review