Ransomware targeting Linux/ESXi has existed since 2015, but since then has gained popularity and become more sophisticated; what was once a niche tool was later adopted by groups focused on “Big Game Hunting” and later became a key piece of ransomware threat actors’ toolkits. Ransomware targeting ESXi has become substantially more popular, and is now used by high-profile groups such as ALPHV, BlackBasta, Royal and LockBit. The shift towards ESXi stems from the virtualization of entire organizations’ infrastructure, with minimal defensive capabilities available. As a result, this provides more incentive for a threat actor looking to extort the organization into paying the ransom. This talk will provide a technical discussion on the evolution of ESXi ransomware and the TTPs ransomware operators employ, including the move to new, cross-compilable languages such as Golang and Rust. I will give a technical overview of modern ESXi lockers, and some of the similarities and differences both with their Windows ransomware versions, and each other. I will also discuss techniques we can use to detect and defend against them, including endpoint and network detection opportunities, and what gaps exist in our ability to do so. Finally, this talk will cover what the future of ransomware could look like, including other opportunities for extortion and additional technologies to exploit that we see in the cybercriminal threat landscape.