Skip to content

GoGoogle

GoGoogle is a ransomware operation known to have developed a Linux encryptor for attacks against VMware ESXi environments.

Profile source: Mallory opens in a new tab

GoGoogle

Family profile

GoGoogle is a ransomware operation known to have developed a Linux encryptor for attacks against VMware ESXi environments. It is part of the broader shift among enterprise-focused ransomware groups toward Linux-based tooling designed to maximize impact in virtualized infrastructure, where compromising a single hypervisor can disrupt many hosted systems at once. Available reporting supports GoGoogle’s use of a Linux encryptor specifically associated with ESXi targeting, but provides limited public technical detail on the family’s internal functionality, encryption workflow, or broader tradecraft compared with better-documented ransomware families. Based on the available facts, GoGoogle should be understood as an ESXi-targeting ransomware threat within the wave of Linux ransomware development aimed at enterprise virtualization platforms.

Capabilities

  • Exfiltration

Observed infrastructure

Last seven days

First activity
Sep 4, 2026
Last activity
Sep 4, 2026
Feed role
Distribution
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Psychz Networks1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

GoGoogle in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.