Cheerscrypt
MITRE ATT&CK: S1096 View on attack.mitre.org
Aliases: Cheerscrypt
- First seen
- 2022-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows, esxi
- Profile updated
- 2026-07-07 13:03:15
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
Cheerscrypt is a ransomware that was developed by Cinnamon Tempest and has been used in attacks against ESXi and Windows environments since at least 2022. Cheerscrypt was derived from the leaked Babuk source code and has infrastructure overlaps with deployments of Night Sky ransomware, which was also derived from Babuk.
Detection coverage
- 60 Sigma rules
Malware & tools used
- Service Stop (attack-pattern)
- Hypervisor CLI (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Virtual Machine Discovery (attack-pattern)
Used by threat actors
- Cinnamon Tempest (threat-actor)
Reports & references
- blog.sygnia.co — Revealing Emperor Dragonfly A Chinese Ransomware Group (report)
- Trend Micro — New Linux Based Ransomware Cheerscrypt Targets Exsi Devices (report)
- MITRE ATT&CK — S1096 (report)