Eclipse: a new ransomware crew advertises a $70,000 floor and post-quantum encryption
Eclipse is a newly advertised ransomware-as-a-service operation offering affiliates a 90/10 split, refusing cases under $70,000, and claiming ChaCha20 and Kyber encryption across Windows, ESXi and Nutanix. Everything known comes from its own recruitment advertising.
A new ransomware-as-a-service operation calling itself Eclipse is recruiting affiliates, and its pitch is worth reading. Not because the crew has done anything yet, but because of what the sales copy says about where this end of the market is going. Nothing here has been seen in an incident. Everything below is what Eclipse advertises to the criminals it wants to hire, surfaced by Flare's Tammy Harper and mirrored on RansomLook. Read it as a brochure, not a post-mortem.
The commercial terms come first, because they set the floor. Affiliates keep 90 per cent of the first ten payments and 80 per cent after that. There is a $300 entry fee, refunded against the first payout, and a rule that the crew will not take a case where the ransom demand would be below $70,000. Discounts to victims are capped at 30 per cent of the opening demand. This is not a smash-and-grab outfit chasing volume. It is positioning itself upmarket, with a negotiation team, a management panel, per-case BTC/XMR wallets and 2FA on the panel using HOTP/TOTP. The framing throughout is corporate, and that is the point of it.
The technical claims are the part defenders should actually note. Eclipse advertises ChaCha20 paired with Kyber and markets the combination as post-quantum. That label is mostly marketing, since a symmetric cipher like ChaCha20 is already considered quantum resistant, but the practical implication holds either way. If the implementation is sound there is no cryptographic shortcut to recovering what Eclipse encrypts, which puts the whole weight of your response on the backups. Lockers are advertised for Windows, written in Rust, and for Linux and NAS, ESXi and Nutanix, written in C++, with a single Linux and NAS build that detects the platform and an ESXi build claimed to run on every version from 4.0 upward. Configurable encryption modes run from a 3 per cent ultrafast pass up to full encryption, the usual trade of speed against thoroughness.
Look at what the feature list keeps returning to, and it is your recovery infrastructure. The Windows locker advertises encryption of Hyper-V virtual machines and of Veeam Backup & Replication backups, named explicitly. The Nutanix build claims it will encrypt immutable snapshots where they are reachable, and shut down every virtual machine and service before encrypting from the root. Tape backup destruction and a cloud backup tool are listed as in development. This is a crew that has read the incident response playbook and is selling the counter to it, to other criminals. The rest of the Windows feature set is standard modern kit: propagation over network shares, Group Policy and PsExec/WMI, disabling Defender, deleting shadow copies, clearing logs, Safe Mode operation, and EDR killers offered to VIP affiliates.
The affiliate rules carry the usual tells. No attacks on CIS or former Soviet states, which places the operators, and no children's healthcare or nonprofits, which is reputation management rather than conscience. Everything else is explicitly fair game, and the permitted list names critical infrastructure, pipelines, oil and gas facilities, government at any level, the military and the nuclear energy sector. A crew advertising a $70,000 floor and pipeline targeting in the same breath is telling you which victims it expects to pay.
For defenders, the advertised capabilities point straight at the hardening that matters. Backups only count if the ransomware cannot reach them, which means immutable storage that is genuinely immutable rather than merely labelled so, offline or air-gapped copies, and Veeam and Hyper-V infrastructure isolated from the domain it is meant to protect. Prove it with a restore test rather than a policy document. Because the kit leans on Group Policy, PsExec and WMI to spread, constrain those lateral movement paths and watch for their abuse. Turn on tamper protection for your endpoint tooling, because the EDR killer offering assumes you have not. And harden the hypervisors directly, ESXi and Nutanix, not just the guests, because that is where this crew intends to do the damage.

Worth A Note, Not A Panic
Eclipse has no known victims and it may amount to nothing. Plenty of advertised RaaS brands fold quietly before their first attack, and the profile deserves that scepticism. What makes it worth a note is not the crew but the template it represents: a ransomware operation productised to the point of reading like a software launch, with tiered revenue, live chat, 2FA and a public roadmap, built from the outset to target the backup and virtualisation layer that recovery depends on. The marketing language is quantum resistant encryption and professional negotiators. The engineering priority, read off the feature list, is making sure you cannot restore. Plan around the priority, not the brand.