logo

Agenda Ransomware Targets ESXi and vCenter Servers (Campaign)

ID: 620f93ef-6431-5a34-96f8-127dd760e234

STIX ID: report--620f93ef-6431-5a34-96f8-127dd760e234

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2024-03-26

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed the Agenda (Qilin/Water Galura) ransomware group increasingly targeting organizations worldwide — notably in the US, Argentina, Australia, and Thailand — by leveraging a Rust ransomware variant and sophisticated deployment and lateral-movement techniques. The group uses RMM tools, Cobalt Strike, PsExec, SSH, and a custom PowerShell script to propagate to VMware vCenter and ESXi servers, employs BYOVD (vulnerable drivers) to evade defenses, and has added unusual tactics such as printing ransom notes to networked printers, posing a significant threat to virtualized infrastructure and targeted sectors (finance, law).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.