ESXWhy: A Look at ESXiArgs Ransomware
ID: 2221612c-e6cb-51a6-a457-e6ec395f29f2
STIX ID: report--2221612c-e6cb-51a6-a457-e6ec395f29f2
Feed Name: Censys Blog
Date Published: 2023-02-09
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
**Executive summary:** The Censys ARC report documents the ESXiArgs ransomware campaign (early February 2023) that leverages a VMware ESXi/OpenSLP vulnerability (CVE-2021-21974) to encrypt virtual machines on internet-facing ESXi hosts; the campaign has infected thousands of hosts (peak ~3,500–3,800), is concentrated in France and OVH infrastructure, has evolved to a variant that encrypts more data and removes BTC addresses to hinder tracking, and has at least some observed payments (~$88k) while defenders publish decryptors and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
