logo

ESXiArgs: What you need to know and how to protect your data

ID: 1d696ec1-e1cb-50dc-a7c8-b7a8c427bcd4

STIX ID: report--1d696ec1-e1cb-50dc-a7c8-b7a8c427bcd4

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

This report details the ESXiArgs ransomware campaign (observed circa Feb 2023) that exploits a known OpenSLP RCE (CVE-2021-21974) to deploy an encryptor which targets VM disk and memory files on vulnerable VMware ESXi hosts; it documents the attack script behavior, filesystem and service modifications, IOCs (filenames, hashes, modified config files, TOX ID), and provides mitigation and recovery guidance including patching and a CISA recovery script.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.