Eclipse — Ransomware Profile
Eclipse is a ransomware-as-a-service operation advertised on cybercrime forums by a handle calling itself EclipseSupport, reported publicly on 12 August 2026. Read almost everything known about it as a sales pitch rather than as observed tradecraft: the operator claims a Rust encryptor for Windows and C++ builds for Linux, NAS appliances, VMware ESXi and Nutanix, ChaCha20 encryption with a Kyber post-quantum key exchange, routines that encrypt Hyper-V virtual machines and disable Veeam backup infrastructure, and configurable modes that trade speed against stealth. None of that has been independently confirmed in a real intrusion. The affiliate terms are more revealing than the cryptography, because they describe the business it wants: a 300 dollar entry fee refundable on first payout, a 90/10 split favouring affiliates for their first ten cases and 80/20 after, and a stated minimum target payout of 70,000 dollars, which sets the floor for the size of victim it is recruiting people to attack. The panel offers multi-user team access, automated payment validation, per-victim Bitcoin and Monero wallets, dedicated Tor negotiation addresses and leak-site publishing. We record one victim so far, a Singapore-based company named on the group's onion site on 16 August 2026, four days after the advertisement surfaced. That single post is the meaningful data point: it marks the transition from recruitment to naming victims. Treat it as the group's own claim, not a confirmed breach. The risk profile of a new RaaS is scale rather than sophistication, since a platform sold to affiliates gains victims as fast as it gains operators, and the capability set on offer is aimed squarely at the virtualisation and backup layers that determine whether a victim can recover without paying.Also tracked as
EclipseSupport
IntelFusions coverage (2)
- Microsoft fixes 421 flaws as new Defender zero-day drops 2026-08-12 · Vulnerabilities
- Fake Roblox cheat hands attackers full control of PCs 2026-08-03 · Cyber Incidents
Recent claimed victims
- Crystal Pharmatech 2026-08-23
- Moscord 2026-08-16