LIVE
LATEST THREAT: Akira Ransomware 2026: ESXi Targeting, $245M in Payments, and the Linux Encryptor THREAT ALERT ACTIVE
Intelligence DB / Group Profile Helldown

Helldown Ransomware: Group Profile, Zyxel Exploitation, and VMware ESXi Targeting

Helldown emerged in October 2024 exploiting Zyxel firewall zero-days for initial access and has since expanded to Linux and VMware ESXi variants. Despite relatively low victim count, Helldown's willingness to publish data without ransom payment and its VMware encryptor make it a notable threat to mid-market organisations using Zyxel perimeter devices.

By Ransomware Tracker ·
HelldownransomwareZyxelVMware ESXiLinuxzero-daydouble extortiongroup-profile2026
Threat Level
8/10
Sectors Targeted
manufacturing
healthcare
technology
professional-services
Ransomware Family
Helldown

Overview

Helldown surfaced in late October 2024 as a new ransomware operation with a technically distinctive feature: initial access via zero-day vulnerabilities in Zyxel firewall and VPN appliances. The group established a data leak site and claimed its first victims within weeks of becoming active. By mid-2025, security researchers had identified Linux and VMware ESXi variants alongside the original Windows encryptor, completing the pattern of a modern double-extortion operation designed to maximise leverage against organisations with mixed-OS environments and virtualised infrastructure.

Helldown operates as what appears to be a closed group rather than a RaaS — there are no public affiliate recruitment posts, and the victim profile suggests direct operator involvement rather than a network of independent affiliates. Victim count has remained relatively low (approximately 30-40 confirmed victims as of H1 2026) compared to the major RaaS operations, but the group’s willingness to publish exfiltrated data regardless of negotiation status makes it more operationally aggressive than its size implies.

Initial Access: Zyxel Zero-Day Exploitation

Helldown’s defining characteristic in its first months of operation was the exploitation of critical vulnerabilities in Zyxel networking products, specifically SSL VPN and firewall appliances that provide perimeter access to enterprise networks.

The vulnerabilities exploited include CVE-2024-42057 — a command injection vulnerability in Zyxel’s IPSec VPN feature affecting several Zyxel ATP, VPN, and USG FLEX series devices — and related vulnerabilities in the Zyxel web management interface that enabled unauthenticated command execution. Zyxel patched these vulnerabilities in September 2024, but organisations with unpatched appliances remained exposed to Helldown and other groups exploiting the same vulnerability class through early 2025.

The Zyxel exploitation path is particularly effective for ransomware operations because:

  1. Zyxel appliances are widely deployed in mid-market organisations that may have slower patch cadences than enterprise environments
  2. A compromised firewall provides network-level access that bypasses endpoint controls
  3. VPN credentials extracted from the compromised appliance can be used for persistent re-entry even after the initial vulnerability is patched

After gaining initial access via Zyxel, Helldown operators move laterally through the internal network before deploying ransomware — following the standard reconnaissance, credential collection, and lateral movement pattern.

Windows Encryptor

Helldown’s Windows encryptor has characteristics consistent with a custom-developed payload rather than a purchased or leaked builder:

Encryption: AES for file encryption combined with RSA for key protection. Files are encrypted in place and renamed with a .helldown extension.

Shadow copy deletion: Standard vssadmin commands are executed to remove Volume Shadow Copies before encryption, preventing local recovery.

Process termination: Database, backup, and business application processes are terminated prior to encryption to ensure file handles are released.

Ransom note: A file named Qdz1N.README.txt (or similar randomly generated filename) is dropped in each encrypted directory. The note directs victims to a Tor-hosted negotiation portal and provides a unique victim ID.

Data theft prior to encryption: Exfiltration precedes encryption. The group uses standard tools — WinRAR for archiving, and cloud storage services or their own infrastructure for exfiltration — before deploying the encryptor. Victims who refuse payment face publication of the stolen data on Helldown’s leak site.

Linux and VMware ESXi Variant

In mid-2025, researchers identified Linux and ESXi variants of the Helldown encryptor. The Linux variant targets VMware Virtual Machines directly, encrypting .vmdk (disk), .vmx (configuration), and .nvram files. By targeting VMs at the hypervisor level rather than within each guest OS, the encryptor can simultaneously impact all virtual machines running on a host without needing to compromise each one individually.

The ESXi variant showed characteristics of code derived from leaked source code from the Babuk ransomware family — a pattern seen in several other ESXi-targeting ransomware operations including Akira’s Linux variant and several others. The Babuk ESXi code provides a working template for encrypting VMware storage formats that multiple groups have adapted.

Why ESXi targeting matters: Many mid-market organisations have consolidated their Windows server infrastructure onto VMware vSphere or ESXi. An encryptor that operates at the hypervisor level can take down an entire virtual server estate in minutes — domain controllers, file servers, database servers, and business applications simultaneously — with a single successful deployment on the ESXi host.

Data Leak Site

Helldown operates a Tor-hosted leak site that functions as leverage in ransom negotiations. The site has published victim data that includes internal documents, financial records, customer data, and technical documentation. A distinctive pattern: several victims’ data was published with minimal negotiation window, suggesting the group either does not prioritise extended negotiations or uses rapid publication as a pressure tactic rather than a genuine deadline.

The data volumes published have been large in several cases — terabytes rather than gigabytes — suggesting systematic exfiltration of network file shares rather than targeted collection.

Victim Profile

Helldown’s confirmed victims skew toward:

Mid-market technology and manufacturing companies — the Zyxel exploitation bias selects for organisations large enough to have enterprise networking gear but potentially without a 24/7 security operations capability to detect exploitation.

Professional services and healthcare — consistent with most ransomware targeting, where data sensitivity increases leverage.

European organisations — there is a moderate European weighting in confirmed victims, potentially reflecting Zyxel’s market share distribution.

There is no evidence of deliberate sector targeting beyond the Zyxel-based initial access selection effect.

Defensive Implications

Immediate: Any organisation with Zyxel ATP, USG FLEX, or VPN series appliances should verify they are running patched firmware versions addressing CVE-2024-42057 and related vulnerabilities. Unpatched Zyxel devices represent the primary exposure vector for Helldown and other groups exploiting the same vulnerability class.

Network segmentation: Firewall compromise should not be a path to lateral movement across the entire network. Zero-trust segmentation and microsegmentation of server workloads limits the blast radius of a compromised perimeter appliance.

ESXi protection: Hardening recommendations for VMware ESXi environments:

  • Restrict ESXi management interface access to administrative jump hosts only
  • Enable vSphere lockdown mode to prevent direct ESXi console access
  • Ensure ESXi hosts are in a management VLAN inaccessible from workstations
  • Maintain offline backups of VM disk images that cannot be encrypted by a hypervisor-level attack

Backup architecture: The combination of shadow copy deletion and ESXi-level encryption makes local backups ineffective. Air-gapped or immutable off-site backup coverage for critical systems is the primary recovery path for Helldown victims.

EDR coverage: Ensure endpoint detection is deployed on ESXi management hosts and that behavioural detections for ESXi encryption patterns are active. Several EDR vendors added ESXi-specific detections following the broader wave of Linux/ESXi ransomware development in 2024-2025.

Current Status

As of Q2 2026, Helldown remains active. Zyxel patch adoption has reduced the initial access surface available via the original zero-days, and the group’s victim cadence has slowed compared to its peak in late 2024 and early 2025. However, the Linux/ESXi capability means the group can pivot to other initial access methods — purchased access from initial access brokers, phishing, or exploitation of other perimeter vulnerabilities — without losing its most destructive capability against virtualised infrastructure.

// Related Intelligence
Group Profile

Akira Ransomware 2026: ESXi Targeting, $245M in Payments, and the Linux Encryptor

Group Profile

Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure

Group Profile

Embargo Ransomware: Rust-Based RaaS Targeting Enterprise and Healthcare