logo

Cybercriminals Exploit VMware ESXi Vulnerabilities Using Zero-Day Toolset

ID: 6e163fad-5cef-51c7-a07f-969e1040bab0

STIX ID: report--6e163fad-5cef-51c7-a07f-969e1040bab0

Feed Name: GBHackers

Threat Score
92/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** Huntress researchers uncovered the MAESTRO ESXi exploitation campaign that began with a compromised SonicWall VPN and stolen Domain Admin credentials, chained three VMware vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226) to escape the VMX sandbox to kernel level, used KDU to load unsigned drivers, and deployed a VSOCK-based backdoor that evades conventional network monitoring; PDB paths with simplified Chinese and support for 155 ESXi builds indicate a well-resourced Chinese-language developer, and the report provides file-hash IOCs and hardening recommendations including immediate patching and monitoring for unusual VSOCK processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.