logo

China-linked cybercrims abused VMware ESXi zero-days a year before disclosure

ID: 50dbbc79-d7ef-573d-8ca5-7a415e07a956

STIX ID: report--50dbbc79-d7ef-573d-8ca5-7a415e07a956

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-01-09

Date Updated: 2026-04-26

Author: Carly Page

...
...

Researchers at Huntress analyzed a December 2025 intrusion attributed to China-linked actors who used a VMware ESXi VM-escape toolkit—whose development dates back to early 2024—to chain multiple vulnerabilities (CVE-2025-22224/22225/22226) and move from a compromised SonicWall VPN and Domain Admin account to execute code on ESXi hypervisors across more than 150 builds, disabling drivers and loading unsigned kernel modules to remain stealthy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.