Cheerscrypt is a multiplatform ransomware family that emerged in May 2022, initially targeting Linux systems, specifically VMware ESXi environments, before a Windows variant appeared in June 2022. The group's primary motivation is financial gain through multi-extortion, demanding payment for decryption and threatening to leak stolen data. Cheerscrypt is linked to the Chinese hacking group known as 'Emperor Dragonfly,' also tracked as Bronze Starlight by Secureworks and DEV-0401 by Microsoft. A distinguishing characteristic of Cheerscrypt is its direct derivation from the leaked Babuk ransomware builder, sharing significant code similarities, and its unique behavior of renaming target files before encryption, which can lead to encryption failure if file permissions are inadequate.