Cheerscrypt

MITRE ATT&CK: S1096 View on attack.mitre.org

Aliases: Cheerscrypt

First seen
2022-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows, esxi
Profile updated
2026-07-07 13:03:15

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

Cheerscrypt is a ransomware that was developed by Cinnamon Tempest and has been used in attacks against ESXi and Windows environments since at least 2022. Cheerscrypt was derived from the leaked Babuk source code and has infrastructure overlaps with deployments of Night Sky ransomware, which was also derived from Babuk.

Detection coverage

  • 60 Sigma rules

Malware & tools used

  • Service Stop (attack-pattern)
  • Hypervisor CLI (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Virtual Machine Discovery (attack-pattern)

Used by threat actors

Reports & references

  • blog.sygnia.co — Revealing Emperor Dragonfly A Chinese Ransomware Group (report)
  • Trend Micro — New Linux Based Ransomware Cheerscrypt Targets Exsi Devices (report)
  • MITRE ATT&CK — S1096 (report)

External references