A new ransomware-as-a-service operation has surfaced on underground forums, and it comes with the kind of polish that has become standard in the cybercrime economy. The threat actor operating under the handle EclipseSupport is actively promoting Eclipse Ransomware, a platform built to let affiliates run extortion campaigns against Windows, Linux, and ESXi infrastructure without needing deep technical skills of their own.

What makes this development worth paying attention to isn't just the malware itself. It's the business model wrapped around it, one that mirrors legitimate software-as-a-service products in almost every respect except the intent behind them.

Inside the Eclipse Ransomware RaaS Platform

According to reporting on the operation, Eclipse Ransomware functions as a fully managed affiliate ecosystem. At the center of it sits an administrative web panel that gives operators centralized control over active campaigns. The panel supports multi-user team access, meaning affiliate groups can collaborate on operations rather than working in isolation, and it includes automated payment validation to streamline the collection of ransom payments once victims decide to pay.

Real-time activity logging gives affiliates and the platform's developers visibility into how campaigns are progressing, while an integrated LiveChat portal handles the most uncomfortable part of the process directly: negotiating with victims. This kind of built-in communication tooling has become a hallmark of modern ransomware operations, allowing extortion groups to pressure victims in real time without relying on third-party messaging apps or email.

The developers behind Eclipse also lean on double extortion, a tactic that has become the default across the ransomware landscape. Rather than simply encrypting files and demanding payment for a decryption key, attackers first exfiltrate corporate data and threaten to publish it publicly if the ransom isn't paid. This gives victims two separate reasons to comply, even if they have solid backups that would otherwise let them recover without paying.

By targeting Windows, Linux, and ESXi environments specifically, Eclipse is positioning itself to hit the infrastructure that underpins most modern enterprise networks. ESXi in particular is a popular target for ransomware groups because a single compromised hypervisor host can lead to the encryption of dozens of virtual machines at once, dramatically amplifying the damage from one successful intrusion.

Why RaaS Platforms Keep Multiplying

The RaaS model lowers the barrier to entry for cybercrime substantially. Instead of needing to build encryption tools, negotiation infrastructure, and payment systems from scratch, affiliates can rent access to an established platform and focus purely on breaking into networks. Developers, in turn, take a cut of the proceeds, creating a recurring revenue stream that incentivizes continuous feature development, exactly the kind of dynamic that has driven the professionalization of ransomware over the past several years.

This is part of a broader pattern where the tools used to compromise networks in the first place are also evolving quickly. Unpatched vulnerabilities in widely used software remain one of the most common entry points for ransomware affiliates. Recent examples include a researcher who dropped yet another Windows zero-day with no vendor fix available, and a separate case where a Windows zero-day called Legacyhive was leaked by a frustrated security researcher. Each unpatched flaw represents a potential doorway for exactly the kind of affiliate groups that platforms like Eclipse are designed to support.

Microsoft's own patching cadence underscores the scale of the challenge defenders face. The company recently issued a record 570 security fixes in a single Patch Tuesday release, including fixes for actively exploited zero-days. That volume of vulnerabilities, arriving on a near-constant basis, gives ransomware affiliates a steady supply of potential attack paths, especially in organizations that struggle to keep patching schedules current across large Windows and Linux fleets.

What This Means For You

If you manage IT infrastructure, whether at a small business or a larger enterprise, the emergence of Eclipse Ransomware is a reminder that ransomware-as-a-service platforms are lowering the skill threshold for attackers while raising the operational sophistication of attacks themselves. Affiliates using Eclipse don't need to be malware developers, they just need a way in.

For individuals, the direct exposure to a corporate RaaS platform like Eclipse is limited, but the ripple effects are not. Ransomware attacks on hospitals, service providers, and businesses that hold customer data routinely lead to personal information being published or sold when double extortion demands go unpaid. That means the data you've shared with any organization running Windows, Linux, or ESXi infrastructure could end up caught in a future incident tied to this or a similar platform.

Practical Steps Worth Taking

Organizations running ESXi hosts or mixed Windows and Linux environments should treat patch management as a priority rather than a routine task, since unpatched systems remain the most common entry point for ransomware affiliates. Segmenting networks so that a single compromised host can't cascade into a full environment takeover is equally important, particularly for virtualization infrastructure where one hypervisor breach can affect dozens of machines.

Maintaining offline, tested backups remains one of the few reliable defenses against the encryption side of these attacks, though it won't protect against the data-leak threat that double extortion relies on. That's why limiting the sensitive data stored on internet-facing systems, and encrypting what must be stored, matters just as much as backup strategy.

For everyday users, the best defense is indirect but still meaningful: use unique passwords across services, enable multi-factor authentication wherever it's offered, and pay attention to breach notifications from companies you do business with. The Eclipse Ransomware RaaS platform is a new entrant in a crowded field, but the fundamentals of protecting against its downstream effects haven't changed.