Last seven days
- First activity
- Sep 4, 2026
- Last activity
- Sep 4, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
GoGoogle is a ransomware operation known to have developed a Linux encryptor for attacks against VMware ESXi environments.
Profile source: Mallory opens in a new tabGoGoogle
GoGoogle is a ransomware operation known to have developed a Linux encryptor for attacks against VMware ESXi environments. It is part of the broader shift among enterprise-focused ransomware groups toward Linux-based tooling designed to maximize impact in virtualized infrastructure, where compromising a single hypervisor can disrupt many hosted systems at once. Available reporting supports GoGoogle’s use of a Linux encryptor specifically associated with ESXi targeting, but provides limited public technical detail on the family’s internal functionality, encryption workflow, or broader tradecraft compared with better-documented ransomware families. Based on the available facts, GoGoogle should be understood as an ESXi-targeting ransomware threat within the wave of Linux ransomware development aimed at enterprise virtualization platforms.
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.