Aleks Ransomware Decryptor and Recovery
How to Remove Aleks Ransomware and Decrypt Your Data?
Introduction
The Aleks ransomware represents a calculated evolution in virtualization-targeted extortion. Rather than relying on generic Windows-based payloads that encrypt mapped network drives, Aleks is a statically linked Linux ELF binary engineered specifically for VMware ESXi environments (versions 6.5, 6.7, and newer). When deployed, it aggressively terminates snapshots via vim-cmd, modifies hypervisor firewall rules, and completely disables all hosted virtual machines by appending the .aleks extension to critical datastore files.
Related article: How to Remove LockBit 3.0 Black Ransomware and Protect Your Data?
The Aleks Decryptor Tool: Advanced Recovery Strategies
Because Aleks utilizes a robust Rust-based cryptographic implementation (leveraging crates like rand_chacha and ppv-lite86), mathematical brute-forcing of the cipher is not feasible. However, forensic analysis of active attacks has revealed critical operational anomalies within the .aleks execution sequence.
The ransomware processes files sequentially, handling small files first and explicitly deferring files larger than 100 MiB to a secondary pass. Entropy analysis of multi-gigabyte files (such as database ISOs or massive VMDKs) has shown that the beginning of these large files often remains entirely unencrypted, with high-entropy (encrypted) data only appearing much deeper in the file offsets. A professional Decryptor and DFIR service can exploit this “skip logic” or interrupted execution state to successfully reconstruct virtual machine data from the unencrypted headers and unallocated datastore space.
Targeting Virtual Infrastructures: The Aleks Assault on ESXi
How it Works: Key Features and Tactics
- Initial Access: The threat actors typically gain entry via exposed SSH ports using compromised or reused root credentials, completely bypassing standard vulnerability exploits (CVEs).
- Firewall Sabotage: The binary actively modifies the ESXi host firewall to permit outbound TCP traffic on ports 8080 and 32921, establishing communication with its embedded Command and Control (C2) server (e.g.,
66.23.235[.]118). - System Sabotage: Before encryption begins, the payload executes the internal log tag
[wipesnap], utilizing nativevim-cmdcommands to purge all virtual machine snapshots and eliminate local rollback options.
The Persistence Mechanism (The “Fake” VMTools)
To ensure the encryption process survives hypervisor reboots, Aleks deploys a highly deceptive persistence mechanism. It drops the malicious 628KB ELF binary as a hidden file named .vmtoolsd in the /etc/vmware/ directory—mimicking the legitimate VMware Tools daemon located in /usr/lib/vmware-tools/. It then writes the following entry to the host’s cron jobs, ensuring the encryptor restarts every 15 minutes:
Threat Intelligence & Forensic Artifact Matrix
Detecting and isolating the Aleks payload requires strict adherence to the following Indicators of Compromise (IOCs):
| Forensic Parameter | Observed Technical Indicator |
|---|---|
| Appended File Extension | .aleks |
| Ransom Note Filename | aleksan_help.txt |
| Primary Communication | aleksandra@msg.ws |
| Secondary Contact (Tox/Session) | Session ID: 05357990f3decfbe9873858f0d30b376a15536d43384b55c38df607d95377ba908 |
| Malicious Binary Path | /etc/vmware/.vmtoolsd |
| Identified C2 Infrastructure | 66.23.235[.]118 |
How to Contain and Remove Aleks Ransomware?
If your ESXi cluster is actively under attack, IT administrators must execute immediate containment protocols to stop the 15-minute cron cycle:
- Halt the Cron Job: Log into the ESXi shell via SSH. Remove the malicious cron entry by editing
/var/spool/cron/crontabs/rootand restarting the cron service. - Terminate the Process: Execute
kill -9 $(pgrep -f .vmtoolsd)to immediately stop the active encryption loop. - Delete the Payload: Remove the hidden executable located at
/etc/vmware/.vmtoolsd. - Block C2 Traffic: Restore your ESXi firewall configurations and block all outbound communication to the attacker’s IPs at the perimeter hardware firewall.
Context of the Ransom Note
The ransomware drops the aleksan_help.txt file across the corrupted datastores, explicitly utilizing the Session secure messaging application for negotiations:
Building a Unified Defense Against ESXi Ransomware
To protect against Aleks and similar hypervisor threats, implement the following infrastructure hardening measures:
- Disable SSH Access: The ESXi Secure Shell should only be enabled strictly during active maintenance windows. It must be disabled for normal production operations to prevent credential abuse.
- Enforce Strict Access Controls: Change root passwords immediately if credential reuse is suspected. Restrict ESXi management interfaces to dedicated, heavily monitored management VLANs.
- Immutable Hypervisor Backups: Maintain encrypted, off-site backups of your datastores. Ensure your backup software utilizes immutable storage architectures (WORM) that cannot be deleted even if the ESXi root account is compromised.
Free Alternatives for Data Recovery
If professional forensic recovery is not viable, consider these methods:
- Restore from Isolated Backups: Rebuild the ESXi host entirely (to wipe persistence hooks) and restore VM images from a secure backup server.
- Data Carving on Large Files: Because Aleks defers files over 100 MiB and may interrupt encryption runs, data recovery software designed for raw disk carving might successfully extract intact internal databases or files from the unencrypted headers of massive
.vmdkfiles.
Conclusion
The Aleks ransomware is a surgically precise threat designed to cripple VMware ESXi infrastructure by leveraging compiled Rust binaries and native hypervisor commands. However, its sequential processing logic and handling of large files present distinct opportunities for advanced data recovery. By neutralizing its persistence mechanisms, securing root access, and engaging professional forensic engineers to analyze file entropy anomalies, organizations can recover from this devastating attack without negotiating with cybercriminals.
Contact Us To Secure Your Recovery
If your ESXi cluster has been compromised by the Aleks payload, do not negotiate with the threat actors on the Session app. Contact our specialized laboratory team immediately to evaluate your corrupted datastores, analyze encryption anomalies, and commence secure data restoration.
Frequently Asked Questions
.aleks extension to virtual machine files and disables entire server clusters simultaneously..vmtoolsd in the /etc/vmware/ directory (mimicking the legitimate VMware Tools daemon) and creates a cron job that ensures the encryptor restarts every 15 minutes..vmsd and .vmx.lck lock files) and sequentially processes small files first, actively deferring files larger than 100 MiB to later in its execution cycle.vim-cmd commands to wipe all local VM snapshots, effectively destroying standard rollback points on the host..vmdk files, reconstruct unencrypted file headers, and safely restore your virtual machines.




