logo

Chinese-speaking hackers exploited ESXi zero-days long before disclosure

ID: 1c043e3b-9ba9-5db4-85d2-56d768856e10

STIX ID: report--1c043e3b-9ba9-5db4-85d2-56d768856e10

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Chinese-speaking attackers leveraged a compromised SonicWall VPN to deploy a sophisticated ESXi exploit toolkit (MAESTRO) that chains an information leak, VMCI/HGFS memory corruption, and an unsigned kernel driver to escape VM isolation, then installed a stealthy VSOCK-based backdoor (VSOCKpuppet); Huntress analysis and embedded PDB paths indicate the exploit was developed and likely used as a zero-day as early as February 2024, and VMware later patched the related CVEs in VMSA-2025-0004.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.