Ransomware changed targets, and the new target concentrates everything a company needs to keep running.
In 2026, the most active groups stopped spending ammunition machine by machine. The effort moved up the stack: to the hypervisor. Whoever controls the hypervisor controls dozens of virtual machines, scheduling, storage, and, in most poorly protected setups, the backup itself.
The new target: the hypervisor
Akira, Qilin, and DragonForce stopped aiming only at workstations and started concentrating effort on VMware ESXi, Hyper-V, and Nutanix. The logic is cold and economic: encrypting one virtualization host takes down dozens of workloads with a single lateral move.
The technical pattern the reports describe is always the same tripod:
- No multi-factor authentication on hypervisor management: one stolen credential from a phishing email is enough.
- No dedicated protection layer on the hypervisor: the VM’s antivirus cannot see the host that runs it.
- Network-reachable backups: the repository meant to save the operation sits inside the radius of the same compromise.
With that tripod, the attacker does not encrypt one machine. They take down virtualization, backup, and operations at the same time. That is the cascading attack: nobody can restore anything, because whatever would do the restoring was encrypted too.
Brazil at the top of the list
Brazil is not a secondary target in this story. July 2026 reports from ISH Tecnologia, Brandefense, and Derp ponto ca place the country among the five most attacked, alongside the United States, Italy, Germany, and Mexico. Brandefense highlighted LockBit 5 among the fastest-growing groups in Q2. ISH confirmed manufacturing as the most attacked industry of the quarter, with Qilin in the lead, and technology as the second sector, followed by business services.
The sector data matches the global map: according to Guidepoint Security’s GRIT Q2 2026, manufacturing accounted for 22% of ransomware victims in the analyzed window, with 1,660 victims counted. We have covered before Brazil in the top 3 for ransomware with The Gentlemen and the Fortigate worm: the country keeps showing up on major groups’ radar with growing regularity, and the vector changes, but the position does not.
The cascade the Nichirei case taught
The case that best illustrates the cascade came from Japan: RansomHouse’s attack on Nichirei, a cold chain giant, halted the refrigerated supply chain and impacted restaurant operations such as KFC in the country. A frozen logistics chain depends on IT to run; the IT depended on virtualization; the virtualization went down.
This is not a food-industry-only pattern. The Fairlife case, from the Coca-Cola group, with Anubis and its data-wipe mode, showed the same mechanics in another cold chain: when concentrated infrastructure falls, the physical operation stops with it. In Brazil, with manufacturing at the top of attacked sectors, the hypervisor is the functional equivalent of the Japanese cold chain: the single point where the entire operation depends on a layer almost nobody watches.
The reachable backup is the link that breaks recovery
The cruelest part of the design is not the VM encryption. It is the backup’s.
Backup is the right answer to ransomware, but only when it sits outside the attacker’s reach. In the diagnostics we run, the backup repository is usually mounted on the same network, with shared administrative credentials and, sometimes, the hypervisor itself doing the backup agent’s job. In that design, compromising the host means compromising the safety copy in the same session.
Backup that survives ransomware requires separation: its own credentials, a segmented network, and at least one immutable or offline copy. The test is simple to run and uncomfortable to answer: can the hypervisor administrator account delete the backup? If yes, so can the attacker.
What to do now
The answer to the hypervisor as a target is not a product; it is an architecture of small decisions: lock down management, enforce MFA, separate the backup, segment virtualization traffic, and actually test restoration. No item is expensive or exotic. What is expensive is the day all five gaps exist at once and a group like Qilin finds all of them.
For companies that need to structure this shielding with a team that operates critical infrastructure every day, Tech86’s cybersecurity hub concentrates the set: perimeter WAF, endpoint EDR, and incident response with a Portuguese-speaking team that knows the Brazilian threat landscape.
Conclusion
Ransomware did not get more creative: it got more efficient. Aiming at the hypervisor is the rational choice for anyone seeking maximum damage for minimum effort, and the numbers put Brazil at the center of that bill.
Is your backup reachable by the hypervisor administrator account? If the answer is "I don't know", that is the gap. Close the tripod (MFA, dedicated protection, backup out of reach) before a quarterly report cites you as a victim.