Agenda Ransomware Targets ESXi and vCenter Servers (Campaign)
ID: 620f93ef-6431-5a34-96f8-127dd760e234
STIX ID: report--620f93ef-6431-5a34-96f8-127dd760e234
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-03-26
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers observed the Agenda (Qilin/Water Galura) ransomware group increasingly targeting organizations worldwide — notably in the US, Argentina, Australia, and Thailand — by leveraging a Rust ransomware variant and sophisticated deployment and lateral-movement techniques. The group uses RMM tools, Cobalt Strike, PsExec, SSH, and a custom PowerShell script to propagate to VMware vCenter and ESXi servers, employs BYOVD (vulnerable drivers) to evade defenses, and has added unusual tactics such as printing ransom notes to networked printers, posing a significant threat to virtualized infrastructure and targeted sectors (finance, law).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
