logo

Ransomware operators exploit ESXi vulnerability (Campaign)

ID: 52ced8ca-b3a4-592b-89a9-d30006d24977

STIX ID: report--52ced8ca-b3a4-592b-89a9-d30006d24977

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2024-07-29

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Microsoft researchers disclosed CVE-2024-37085 affecting VMware ESXi hypervisors: a default Active Directory group name "ESX Admins" can be used (or created/renamed) to obtain full administrative privileges on domain-joined ESXi hosts, allowing attackers to access and encrypt guest VMs and move laterally. The flaw is being actively exploited by ransomware operators (e.g., Storm-0506 and Storm-1175) to deploy ransomware such as Akira and Black Basta; operators can exploit group creation/renaming or delayed privilege refresh. Organizations should upgrade ESXi to the latest versions and review AD group naming and privilege handling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.