ESXiArgs: What you need to know and how to protect your data
ID: 1d696ec1-e1cb-50dc-a7c8-b7a8c427bcd4
STIX ID: report--1d696ec1-e1cb-50dc-a7c8-b7a8c427bcd4
Feed Name: TrustedSec blog
Threat Score
This report details the ESXiArgs ransomware campaign (observed circa Feb 2023) that exploits a known OpenSLP RCE (CVE-2021-21974) to deploy an encryptor which targets VM disk and memory files on vulnerable VMware ESXi hosts; it documents the attack script behavior, filesystem and service modifications, IOCs (filenames, hashes, modified config files, TOX ID), and provides mitigation and recovery guidance including patching and a CISA recovery script.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
