logo

Censys in the News: ESXiArgs Ransomware Coverage

ID: 1f3ab0f5-a0d8-52cc-b652-253d49677e42

STIX ID: report--1f3ab0f5-a0d8-52cc-b652-253d49677e42

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2023-02-18

Date Updated: 2026-04-27

Author: Ivonne Francia

...
...

The Censys research team tracked an active ESXiArgs ransomware campaign against VMware ESXi servers beginning in early February, observing a global outbreak (peak ~3,551 infected hosts), visible ransom pages and bitcoin addresses, evidence of payments tracking, and attacker changes that rendered a CISA recovery tool ineffective; Censys published a dashboard and findings that were widely cited in industry press.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.